Description
Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN eSettlements accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE‑2026‑61057 details a weakness in the eSettlements component of Oracle PeopleSoft Enterprise FIN 9.2 that allows an attacker to perform unauthorized write, update, delete, and read operations through HTTP requests without authentication. The flaw, classified as CWE‑284, is caused by insufficient access controls that do not enforce proper authorization checks, enabling manipulation of financial records and leakage of sensitive data. In a successful exploitation, an attacker can alter or expunge accounting information and gain read access to files or transaction data that should remain confidential, thereby compromising the integrity and confidentiality of the system.

Affected Systems

Oracle PeopleSoft Enterprise FIN eSettlements software version 9.2 is the only product and version identified as affected in the advisory. No other editions or client applications are mentioned, and the issue is not reported for earlier or later releases.

Risk and Exploitability

The CVSS 3.1 base score of 4.8 indicates a moderate risk that impacts confidentiality and integrity, while a very low EPSS score of < 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote, accessed over HTTP, and requires no prior authentication; an attacker who can send HTTP requests to the eSettlements endpoints can directly modify or read data.

Generated by OpenCVE AI on August 4, 2026 at 02:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update for PeopleSoft Enterprise FIN eSettlements 9.2 addressing the access control issue.
  • Restrict HTTP access to the PeopleSoft application to trusted hosts or internal networks only.
  • Enforce authentication and proper authorization checks on all eSettlements endpoints to prevent unauthenticated access.

Generated by OpenCVE AI on August 4, 2026 at 02:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification and Read in PeopleSoft eSettlements

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification and Read in PeopleSoft eSettlements

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification in PeopleSoft Enterprise FIN eSettlements

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification in PeopleSoft Enterprise FIN eSettlements
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN eSettlements accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Esettlements
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_esettlements:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Esettlements
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Esettlements
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:26:37.270Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61057

cve-icon Vulnrichment

Updated: 2026-07-24T14:26:30.674Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses