CVE-2026-61235
CVE-2026-61235 is a critical vulnerability (CVSS 9.1) in Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland version 9.2. It allows a high‑privileged attacker with network access via HTTP to compromise the component, potentially leading to full takeover and impacting other products due to scope change. No public exploit or known‑exploited status is reported.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2 users.
Real-world impact
Successful exploitation could give an attacker complete control of the affected payroll system and affect related products.
Why this severity
The CVSS v3.1 base score of 9.1 reflects high impacts to confidentiality, integrity, and availability, with low attack complexity and no user interaction required.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources