Description
Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN eSettlements executes to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an attacker who already has high privileged local logon to the infrastructure hosting Oracle PeopleSoft Enterprise FIN eSettlements to read a subset of the application data, thereby compromising confidentiality. It is a CWE‑306 flaw and a low‑severity issue but results in information leakage to a privileged attacker.

Affected Systems

Oracle PeopleSoft Enterprise FIN eSettlements version 9.2, deployed on enterprise infrastructure; the affected component is eSettlements.

Risk and Exploitability

With a CVSS base score of 2.3 and an EPSS score of less than 1%, the risk of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. An attacker must already possess local high‑privilege access; no network or user‑interaction vector is required. The flaw can lead to unauthorized read access to a subset of sensitive data, limited to confidentiality impact only.

Generated by OpenCVE AI on August 5, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any Oracle update that addresses the unauthorized data read vulnerability for PeopleSoft Enterprise FIN eSettlements 9.2.
  • Limit local privileged account rights to the minimum necessary for running the PeopleSoft environment, enforcing least privilege.
  • Monitor and audit application logs for anomalous data read activity on the eSettlements component.

Generated by OpenCVE AI on August 5, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Read via Local Privilege on PeopleSoft eSettlements

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Read via Local Privilege on PeopleSoft eSettlements

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑Impact Loss of Confidentiality in Oracle PeopleSoft Enterprise FIN eSettlements
Weaknesses CWE-200
CWE-284

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low‑Impact Loss of Confidentiality in Oracle PeopleSoft Enterprise FIN eSettlements
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN eSettlements executes to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Esettlements
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_esettlements:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Esettlements
References
Metrics cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Esettlements
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:34:53.612Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60596

cve-icon Vulnrichment

Updated: 2026-07-27T15:34:48.997Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function