Description
Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Project Costing executes to compromise PeopleSoft Enterprise FIN Project Costing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Project Costing. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who has local access to the infrastructure hosting PeopleSoft Enterprise FIN Project Costing can compromise the application. The vulnerability requires the attacker to persuade a user to interact with the system, after which the attacker can take over the application, resulting in total loss of confidentiality, integrity, and availability. This attack demonstrates a high-risk local compromise path that can be leveraged if the ad‑hoc environment is not well protected.

Affected Systems

Oracle’s PeopleSoft Enterprise FIN Project Costing, version 9.2, is the only product and version affected by this vulnerability. The weakness exists in the Projects component and applies to installations that run this version within an unprotected local environment.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 base score of 7.8, indicating a medium‑to‑high severity outcome. The EPSS score is below 1 %, reflecting a very low but non‑zero probability of exploitation at the present time, and the issue is not listed in CISA’s KEV catalog. Exploitation requires local access and a user interaction step; no special privileges are needed on the target system. Based on these metrics the risk is considered moderate, but the potential impact warrants immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft Enterprise FIN Project Costing 9.2 patch released in the July 2026 security update
  • Restrict local login to authorized personnel only and enforce strong authentication on infrastructure hosts
  • Configure system logging and monitoring to alert on anomalous activity related to PeopleSoft access

Generated by OpenCVE AI on August 4, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local Access Compromises Oracle PeopleSoft FIN Project Costing 9.2 via Projects Component

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Compromise of Oracle PeopleSoft Enterprise FIN Project Costing
Weaknesses CWE-287

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Compromise of Oracle PeopleSoft Enterprise FIN Project Costing
Weaknesses CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Project Costing executes to compromise PeopleSoft Enterprise FIN Project Costing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Project Costing. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Project Costing
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_project_costing:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Project Costing
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Project Costing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:43:56.357Z

Reserved: 2026-07-08T15:51:40.547Z

Link: CVE-2026-60600

cve-icon Vulnrichment

Updated: 2026-07-27T15:43:47.821Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function