Summary
CVE-2026-61307 is a high-severity vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects, a component of PeopleSoft Enterprise PeopleTools. It allows an unauthenticated attacker with network access via Oracle Net to compromise the affected component, with Oracle stating successful exploitation can result in takeover of the product. Oracle rates the flaw as difficult to exploit, but the potential impact spans confidentiality, integrity, and availability, and it carries a CVSS v3.1 base score of 8.1.
Technical details
- Root cause: Oracle has not published low-level technical details; the flaw resides in the CC Common Application Objects component of PeopleSoft Enterprise PeopleTools 9.2.
- Trigger conditions: exploitation requires network access via the Oracle Net protocol; no authentication and no user interaction are required, though attack complexity is rated high ("difficult to exploit").
- Attack vector: Network (AV:N), reachable without prior authentication (PR:N).
- Impact: successful exploitation can result in complete takeover of the affected PeopleSoft Enterprise CC Common Application Objects instance, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle PeopleSoft Enterprise CC Common Application Objects, version 9.2 (part of PeopleSoft Enterprise PeopleTools deployments)
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the fix issued in Oracle’s August 2026 Critical Patch Update (CSPUAUG2026) for PeopleSoft Enterprise CC Common Application Objects 9.2.
- If patching cannot be applied immediately: restrict and monitor network access to the Oracle Net listener/port used by the PeopleSoft environment, limiting exposure to trusted internal networks only, and review PeopleSoft environments for direct internet exposure of Oracle Net services.
- Follow standard PeopleSoft/PeopleTools hardening guidance and monitor for anomalous activity on internet-facing PeopleSoft assets until patched.

