Description
Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Cash Management executes to compromise PeopleSoft Enterprise FIN Cash Management. While the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Cash Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in PeopleSoft Enterprise FIN Cash Management version 9.2 allows an attacker with basic logon access to the underlying infrastructure to compromise the application. The flaw can be exploited easily at a local level and results in full takeover of the application, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle PeopleSoft Enterprise FIN Cash Management version 9.2 is the primary affected product; the scope change flag indicates that successful exploitation could also impact other integrated products and components.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local or low‑privileged access to the system hosting PeopleSoft; once compromised, the attacker can affect other integrated products as the vulnerability’s scope changes.

Generated by OpenCVE AI on August 4, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch for PeopleSoft Enterprise FIN Cash Management.
  • Disable unused remote services that allow local logon access to the PeopleSoft infrastructure.
  • Enforce least‑privilege access controls on the underlying system.
  • Monitor application logs for anomalous activity.
  • Conduct a database privilege review for PeopleSoft schemas, ensuring only necessary privileges are granted.

Generated by OpenCVE AI on August 4, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full Takeover in PeopleSoft Enterprise FIN Cash Management

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full Takeover in PeopleSoft Enterprise FIN Cash Management

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Cash Management executes to compromise PeopleSoft Enterprise FIN Cash Management. While the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Cash Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Cash Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_cash_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Cash Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Cash Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:20:53.323Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61062

cve-icon Vulnrichment

Updated: 2026-07-24T14:20:47.743Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control