CVE-2026-61204
A critical flaw in Oracle PeopleSoft's Enterprise FIN Program Management (version 9.2) lets a low‑privileged attacker with network access compromise the system. The vulnerability requires a separate user to interact with the system, but once triggered it can lead to full takeover. It affects the Primavera Integration component.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle PeopleSoft Enterprise FIN Program Management, version 9.2, component Primavera Integration.
Real-world impact
An attacker could gain control of the PeopleSoft Enterprise FIN Program Management system, exposing sensitive financial data and potentially disrupting business operations.
Why this severity
The CVSS score of 9.0 reflects that the flaw can be exploited from the network, needs only low privileges, and, if successful, would completely compromise confidentiality, integrity, and availability of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources