Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Common Objects executes to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects accessible data. CVSS 3.1 Base Score 4.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the security component of Oracle PeopleSoft Enterprise FIN Common Objects allows a low‑privileged local attacker to compromise data integrity by creating, deleting, or modifying critical records. The weakness is an instance of unauthorized privilege escalation, improper authorization, and incorrect permissions, and it requires the attacker to have a low‑privileged account with local access and to prompt another user to execute actions. Successful exploitation compromises integrity without directly affecting confidentiality or availability.

Affected Systems

Oracle PeopleSoft Enterprise FIN Common Objects version 9.2 is the only documented affected release. No other versions or product lines are referenced in the advisory.

Risk and Exploitability

The CVSS 3.1 base score of 4.4 indicates a moderate integrity impact. The EPSS score of less than 1 % reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring a low‑privileged account and human interaction from another user. The practical risk is therefore limited to insider or social‑engineering scenarios, but a successful attack would allow unauthorized data modification.

Generated by OpenCVE AI on August 4, 2026 at 03:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s PeopleSoft update repository to confirm whether any security patch or advisory has been issued for the 9.2 release.
  • Restrict the rights of low‑privilege accounts so they cannot create, modify, or delete critical application objects.
  • Deploy staff training and change‑management policies that emphasize the risks of accidental data modification and encourage verification before performing changes.

Generated by OpenCVE AI on August 4, 2026 at 03:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Integrity Compromise via Local Low-Privileged Access in Oracle PeopleSoft Enterprise FIN Common Objects

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Integrity Compromise via Local Low-Privileged Access in Oracle PeopleSoft Enterprise FIN Common Objects

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Data Modification in Oracle PeopleSoft FIN Common Objects
Weaknesses CWE-269
CWE-732

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Data Modification in Oracle PeopleSoft FIN Common Objects
Weaknesses CWE-269
CWE-284
CWE-732

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Common Objects executes to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects accessible data. CVSS 3.1 Base Score 4.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T16:39:34.868Z

Reserved: 2026-07-08T15:51:40.547Z

Link: CVE-2026-60601

cve-icon Vulnrichment

Updated: 2026-07-27T16:39:25.732Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses