Impact
CVE‑2026‑61057 details a weakness in the eSettlements component of Oracle PeopleSoft Enterprise FIN 9.2 that allows an attacker to perform unauthorized write, update, delete, and read operations through HTTP requests without authentication. The flaw, classified as CWE‑284, is caused by insufficient access controls that do not enforce proper authorization checks, enabling manipulation of financial records and leakage of sensitive data. In a successful exploitation, an attacker can alter or expunge accounting information and gain read access to files or transaction data that should remain confidential, thereby compromising the integrity and confidentiality of the system.
Affected Systems
Oracle PeopleSoft Enterprise FIN eSettlements software version 9.2 is the only product and version identified as affected in the advisory. No other editions or client applications are mentioned, and the issue is not reported for earlier or later releases.
Risk and Exploitability
The CVSS 3.1 base score of 4.8 indicates a moderate risk that impacts confidentiality and integrity, while a very low EPSS score of < 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote, accessed over HTTP, and requires no prior authentication; an attacker who can send HTTP requests to the eSettlements endpoints can directly modify or read data.
OpenCVE Enrichment