CVE-2026-61072 Overview
CVE-2026-61072 is a critical vulnerability in the Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil product, within the Staffing component. The affected supported version is 9.1. A low-privileged attacker with network access via HTTP can exploit the flaw to compromise the application. Because the vulnerability triggers a CVSS scope change, successful exploitation may impact additional Oracle PeopleSoft products beyond the vulnerable component. Oracle disclosed the issue in the July 2026 Critical Patch Update advisory.
Critical Impact
Successful exploitation results in complete takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil, with high impact to confidentiality, integrity, and availability across dependent components.
Affected Products
- Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil version 9.1
- Component: Staffing
- Downstream Oracle PeopleSoft components reachable through scope-change exploitation
Discovery Timeline
- 2026-07-21 - CVE-2026-61072 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Disclosed in the Oracle Critical Patch Update advisory
Technical Details for CVE-2026-61072
Vulnerability Analysis
CVE-2026-61072 affects the Staffing component of the PeopleSoft Enterprise FIN Staffing Front Office Brazil product. The Oracle advisory classifies the flaw as easily exploitable over HTTP by an authenticated attacker holding low privileges. No user interaction is required. The scope-change property indicates the vulnerable component can influence resources managed by a separate security authority, extending impact beyond the immediate module. The EPSS probability at publication was 0.447%.
Root Cause
Oracle has not published root-cause internals for CVE-2026-61072. The advisory describes the outcome as full takeover of the Staffing module through network-reachable HTTP interfaces, consistent with insufficient authorization enforcement or unsafe request handling within a low-privilege user context. Refer to the Oracle Security Alert July 2026 for vendor-provided technical details.
Attack Vector
An authenticated attacker with any low-privileged PeopleSoft account sends crafted HTTP requests to the Staffing Front Office Brazil interface. Because the CVSS vector reports a changed scope with high confidentiality, integrity, and availability impact, the attacker can pivot beyond the vulnerable module and exercise control over related PeopleSoft resources. Exploitation requires network access to the application tier and valid, but non-privileged, credentials.
No public exploit or proof-of-concept has been released for CVE-2026-61072. See the Oracle Security Alert July 2026 for authoritative technical detail.
Detection Methods for CVE-2026-61072
Indicators of Compromise
- Unexpected HTTP POST or GET requests from low-privileged accounts to Staffing Front Office Brazil endpoints on PeopleSoft 9.1.
- New or modified PeopleSoft roles, permission lists, or user accounts following anomalous Staffing module activity.
- Outbound connections or data flows from the PeopleSoft application tier that reach components outside the Staffing module scope.
Detection Strategies
- Correlate PeopleSoft application server logs with web tier access logs to identify low-privileged sessions issuing atypical Staffing requests.
- Alert on privilege changes, permission list modifications, and configuration edits that follow Staffing component access.
- Baseline normal Staffing Front Office Brazil traffic patterns and flag deviations in request volume, parameter length, or endpoint diversity.
Monitoring Recommendations
- Enable verbose auditing on the PeopleSoft Staffing component and forward events to a centralized SIEM.
- Monitor authentication events for low-privileged accounts that access Staffing endpoints outside expected business hours.
- Track integration traffic between Staffing Front Office Brazil and dependent PeopleSoft modules to detect scope-change exploitation.
How to Mitigate CVE-2026-61072
Immediate Actions Required
- Apply the July 2026 Oracle Critical Patch Update to all PeopleSoft 9.1 deployments running Staffing Front Office Brazil.
- Inventory PeopleSoft accounts and disable or reduce access for unused low-privileged users that can reach the Staffing module.
- Restrict network reachability of the PeopleSoft web tier to trusted corporate and VPN ranges until patching is complete.
Patch Information
Oracle addressed CVE-2026-61072 in the July 2026 Critical Patch Update. Administrators should review the Oracle Security Alert July 2026 for patch identifiers, prerequisites, and upgrade guidance specific to PeopleSoft Enterprise FIN Staffing Front Office Brazil 9.1.
Workarounds
- Enforce network-level access controls that limit HTTP access to the Staffing Front Office Brazil interface to required users only.
- Apply least-privilege review of PeopleSoft permission lists and remove Staffing access from roles that do not require it.
- Increase logging and session monitoring on the PeopleSoft application tier until the Critical Patch Update is deployed.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

