Junglewise Threat Intelligence

CVE-2026-61242: Oracle PeopleSoft Enterprise FIN Common Objects Argentina takeover in Staffing

CVE-2026-61242 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Argentina. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Staffing component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina. This software is used by organizations to manage financial operations and staffing resources. An attacker with low-level access to the network could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive financial data or a complete disruption of business operations.

Technical details

This vulnerability affects the Staffing component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina, specifically version 9.1. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The exploit results in a scope change (S:C), meaning a successful attack can impact components beyond the immediate PeopleSoft environment. The vulnerability allows for a complete compromise of confidentiality, integrity, and availability, effectively resulting in a full system takeover. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats