PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61201 Oracle Corporation CVE debrief

A critical vulnerability was discovered in PeopleSoft Enterprise CRM Common Objects, which could allow an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability has a CVSS score of 9.0, indicating a high severity level. This vulnerability affects version 9.2.23 of PeopleSoft Enterprise CRM Common Objects and has a significant impact on the system, potentially allowing attackers to take over the system. Organizations should prioritize patching this vulnerability to prevent potential security breaches.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CRM Common Objects
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-06
Advisory published
2026-07-21
Advisory updated
2026-08-06

Who should care

Organizations using PeopleSoft Enterprise CRM Common Objects, version 9.2.23, should prioritize patching this vulnerability to prevent potential takeover of their systems. This is a critical vulnerability with a CVSS score of 9.0, and successful attacks can result in the takeover of PeopleSoft Enterprise CRM Common Objects. IT teams and security professionals responsible for managing and securing PeopleSoft Enterprise CRM Common Objects instances should take immediate action to patch this vulnerability.

Technical summary

The vulnerability is located in the Common Objects component of PeopleSoft Enterprise CRM Common Objects, version 9.2.23. It is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in the takeover of PeopleSoft Enterprise CRM Common Objects. The CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. This vulnerability has a significant impact on the system, and organizations should prioritize patching to prevent potential security breaches.

Defensive priority

High priority should be given to patching this vulnerability due to its critical severity and potential impact on the system.

Recommended defensive actions

  • Apply the patch provided by the vendor as soon as possible
  • Conduct a thorough inventory of PeopleSoft Enterprise CRM Common Objects instances to ensure they are updated to a patched version
  • Implement compensating controls, such as network segmentation or access controls, to limit the attack surface
  • Monitor system logs for suspicious activity
  • Perform regular vulnerability assessments and penetration testing to identify potential vulnerabilities
  • Review and update incident response plans to address potential security breaches
  • Verify the integrity of PeopleSoft Enterprise CRM Common Objects instances after patching

Evidence notes

The CVE record was published on 2026-07-21T22:18:51.837Z and was last modified on 2026-07-22T20:17:05.270Z. The NVD entry is currently in the 'Received' status. The vulnerability has a CVSS score of 9.0 and a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. The source of this information is the NVD entry for CVE-2026-61201. The CVE record provides details on the vulnerability, including its severity, potential impact, and affected products.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61201 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61201

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61201 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61201

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.