CVE-2026-61209
PeopleSoft In-Memory Project Discovery version 9.2 has a critical flaw that lets attackers with network access over HTTP compromise the system. The vulnerability can lead to full takeover, affecting confidentiality, integrity, and availability.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle PeopleSoft In-Memory Project Discovery, version 9.2.
Real-world impact
An attacker could take full control of the PeopleSoft In-Memory Project Discovery service, potentially accessing or altering sensitive data and disrupting business operations.
Why this severity
The CVSS score of 9.9 reflects that the flaw is easy to exploit, requires only low privileges, and can compromise confidentiality, integrity, and availability of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources