CVE-2026-61203
Oracle has fixed 84 vulnerabilities in various modules of Oracle PeopleSoft Enterprise, including HCM Talent Acquisition Manager, In-Memory Project Discovery, FIN Expenses, SCM eProcurement, CC Common Application Objects, SCM Order Management, CRM Common Objects, and FIN Program Management, all version 9.2. Some of these 84 vulnerabilities concern objects that are important for other countries and are therefore not relevant for systems in the Netherlands. The most severe vulnerabilities, 8 in total, have received a high score ranging from 9.1 to 9.9 and are located in various Oracle PeopleSoft Enterprise components. The two most severe vulnerabilities in HCM Talent Acquisition Manager and Project Discovery, with a score of 9.9, allow an attacker with low privileges and network access via HTTP to fully compromise the system. This allows the attacker to affect the confidentiality, integrity, and availability of the environment. The vulnerability may also impact other Oracle products outside the Talent Acquisition Manager module. The vulnerability in Enterprise FIN Expenses, with a score of 9.4, allows unauthenticated external attackers to gain unauthorized access to the system. By exploiting this vulnerability, attackers can modify or delete data within the application. Additionally, the vulnerability can be used to cause a partial denial-of-service (DoS). The vulnerability in SCM eProcurement, with a score of 9.3, allows unauthenticated attackers with network access via HTTP to gain unauthorized access to the system. By exploiting this vulnerability, an attacker can modify critical data within the affected application. The vulnerability may also affect other related Oracle PeopleSoft products.
CSIRTS triage
- What
- The vulnerabilities can lead to full system compromise via HTTP.
- Who is affected
- Deployments of Oracle PeopleSoft Enterprise version 9.2.
- Urgency
- Remediation is critical due to the high severity of some vulnerabilities.
- Action
- Apply the latest patches for Oracle PeopleSoft Enterprise.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-61203
Get an email if CVE-2026-61203 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0260 [1.00] [M/H] Vulnerabilities fixed in Oracle PeopleSoft Enterprisencsc-nl · 2026-07-22
- criticalCVE-2026-61203: Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (componen…nvd · 2026-07-21
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-61203)