Description
Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Pay/Bill Management executes to compromise PeopleSoft Enterprise FIN Pay/Bill Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Pay/Bill Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local low‑privileged attacker who can log on to the infrastructure that runs PeopleSoft Enterprise FIN Pay/Bill Management can exploit an unprotected function in Paybill Management. The flaw allows the attacker to read critical data, potentially obtaining all information exposed by the PeopleSoft application, without affecting integrity or availability. The vulnerability is described as "Easily exploitable vulnerability" that results in unauthorized access to data and is mapped to a CVSS 3.1 score of 5.5 with a high confidentiality impact. This is a privilege escalation flaw (CWE‑306) caused by lack of authentication.

Affected Systems

Oracle PeopleSoft Enterprise FIN Pay/Bill​Management version 9.2 is affected. No other product versions or vendors are listed as impacted.

Risk and Exploitability

The CVSS score of 5.5 places the flaw in the medium‑severity range, but the EPSS score of less than 1 % indicates current exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or internal, requiring a user to have logon access to the host that hosts the PeopleSoft instance. Once logged on, the attacker can gain read‑only access to all sensitive financial data managed by PeopleSoft Pay/Bill Management.

Generated by OpenCVE AI on August 4, 2026 at 17:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released in Oracle CPU Jul 2026 security alert for PeopleSoft 9.2
  • Restrict local system logons to administrators and remove unnecessary accounts
  • Enable auditing of PeopleSoft Pay/Bill Management access and review logs regularly

Generated by OpenCVE AI on August 4, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit in Oracle PeopleSoft Pay/Bill Management Allows Unauthorized Data Access

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Enables Unauthorized Financial Data Access in PeopleSoft Pay/Bill Management
Weaknesses CWE-284
CWE-285

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Enables Unauthorized Financial Data Access in PeopleSoft Pay/Bill Management
Weaknesses CWE-284
CWE-285

Wed, 29 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title PeopleSoft FIN Pay/Bill Management Unauthorized Data Access via Low Privilege Logon
Weaknesses CWE-284
CWE-862

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle peoplesoft Enterprise Fin Pay/bill Management
Vendors & Products Oracle peoplesoft Enterprise Fin Pay/bill Management

Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title PeopleSoft FIN Pay/Bill Management Unauthorized Data Access via Low Privilege Logon
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Pay/Bill Management executes to compromise PeopleSoft Enterprise FIN Pay/Bill Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Pay/Bill Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Pay\/bill Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_pay\/bill_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Pay\/bill Management
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Pay/bill Management Peoplesoft Enterprise Fin Pay\/bill Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:34:18.995Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60595

cve-icon Vulnrichment

Updated: 2026-07-27T15:34:14.433Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function