Description
Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Grants. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Grants accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Grants accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PeopleSoft Enterprise FIN Grants 9.2 contains an access control flaw that allows an unauthenticated attacker who can reach the application over HTTP to modify, insert, or delete data and read a subset of the system's data. This vulnerability provides confidentiality and integrity impacts as reflected by the CVSS 4.8 rating. The weakness is rooted in improper access control (CWE‑284).

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise FIN Grants, version 9.2, is the affected product. The vulnerability is present in the Grants component of that release.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate potential impact, and the EPSS score of less than 1 % shows that this vulnerability is not currently widely exploited. It is not listed in the CISA KEV catalog. An attacker can reach the vulnerable interface directly over HTTP without authentication, satisfying the network attack vector. No prior authentication, privileged access, or user interaction is required, allowing the attacker to modify or read data.

Generated by OpenCVE AI on August 4, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update released in the July 2026 CPU to PeopleSoft Enterprise FIN Grants 9.2.
  • Restrict external HTTP access to the Grants application to trusted networks or enforce network segmentation.
  • Review audit logs for evidence of unauthorized data modifications and enforce stricter access controls.

Generated by OpenCVE AI on August 4, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Read in Oracle PeopleSoft Enterprise FIN Grants

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Read in Oracle PeopleSoft Enterprise FIN Grants

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Grants. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Grants accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Grants accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Grants
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_grants:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Grants
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Grants
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:32:25.845Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61056

cve-icon Vulnrichment

Updated: 2026-07-24T14:32:18.149Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses