CVE-2026-61072: Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (c...
Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Security readout for executives and security teams
Plain-English summary
Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil 9.1 can reportedly be compromised over HTTP by an attacker with a low-privilege account. No user interaction is required. Successful exploitation could permit complete takeover and may affect connected products or trust boundaries. Organizations running this specific product and version should treat remediation as urgent.
Executive priority
Assign critical priority and require rapid ownership, exposure confirmation, and remediation planning. The combination of low attack complexity, modest privilege requirements, no user interaction, complete takeover impact, and potential cross-product consequences creates substantial business risk even without confirmed active exploitation.
Technical view
This is an access-control vulnerability classified as CWE-284. Its CVSS 3.1 score is 9.9: network-accessible, low complexity, low privileges required, no user interaction, changed scope, and high confidentiality, integrity, and availability impact. The supplied sources do not describe the vulnerable endpoint or underlying authorization failure.
Likely exposure
Confirmed exposure is limited to the named PeopleSoft Enterprise FIN Staffing Front Office Brazil product at supported version 9.1. Deployments with HTTP reachable from untrusted networks or broadly accessible internal networks face greater risk. The sources do not identify affected endpoints, default configurations, unsupported versions, or deployment prevalence.
Exploitation context
The vulnerability is described as easily exploitable by a low-privileged attacker with HTTP network access. The supplied bundle reports no CISA KEV listing and provides no evidence of active exploitation or a public exploit. That absence should not be interpreted as proof that exploitation is not occurring.
Researcher notes
The public bundle identifies improper access control and changed scope but provides no endpoint, request flow, authorization boundary, patch identifier, or root-cause detail. Researchers should avoid assuming which interfaces are vulnerable. Validation should focus on authorized product identification, network reachability, account privilege boundaries, remediation evidence, and possible impact on connected systems.
Mitigation direction
Inventory PeopleSoft Enterprise FIN Staffing Front Office Brazil 9.1 deployments and identify their HTTP exposure.
Review Oracle's July 2026 advisory and follow its CVE-specific remediation guidance.
Restrict HTTP access to trusted administrative and business networks until remediation is verified.
Disable unnecessary accounts and minimize privileges for users who can access the affected application.
Increase monitoring for suspicious authentication, authorization, and cross-product activity.
Validation and detection
Confirm the installed product, Staffing component, and version using authoritative inventory or administrative records.
Determine whether application HTTP interfaces are reachable from untrusted or unnecessary network segments.
Verify applicable Oracle guidance and document the required remediation for each deployment.
Confirm remediation using approved patch or configuration evidence rather than network banners alone.
Review relevant HTTP and authentication logs for anomalous low-privilege activity or unexpected downstream access.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-284 · source CWE mapping
Improper Access Control
Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.