Executive brief
A critical vulnerability exists in Oracle's PeopleSoft payroll management software for Switzerland. This software is used by organizations to manage employee compensation and tax compliance. A successful exploit could allow an authorized user with high-level permissions to take complete control of the payroll system, potentially leading to the theft of sensitive financial data, unauthorized salary changes, or disruption of business operations across multiple connected systems.
Technical details
A vulnerability in the Global Payroll for Switzerland component of Oracle PeopleSoft Enterprise HCM version 9.2 allows for a complete system takeover. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact security components beyond the immediate payroll module, potentially affecting other integrated PeopleSoft products or the underlying infrastructure. The exploit impacts the confidentiality, integrity, and availability of the system. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published in Oracle Critical Patch Update