CVE-2026-61307

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CC Common Application Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:peoplesoft_enterprise_cc_common_application_objects:9.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-18 21:16

Updated : 2026-09-04 13:18


NVD link : CVE-2026-61307

Mitre link : CVE-2026-61307

CVE.ORG link : CVE-2026-61307


JSON object : View

Products Affected

oracle

  • peoplesoft_enterprise_cc_common_application_objects
CWE
CWE-284

Improper Access Control

CWE-306

Missing Authentication for Critical Function