Description
Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Billing Argentina. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Billing Argentina. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability enables a highly privileged attacker who can reach the application over HTTP to fully compromise the PeopleSoft Enterprise FIN Billing Argentina system. The flaw is an access control weakness (CWE‑284) and the CVSS 3.1 Base Score of 7.2 reflects significant confidentiality, integrity and availability impacts.

Affected Systems

Oracle’s PeopleSoft Enterprise FIN Billing Argentina, version 9.1 is affected.

Risk and Exploitability

The vulnerability is classified as high severity with a CVSS score of 7.2. The EPSS score is <1%, indicating a low current exploitation probability and the flaw is not listed in CISA’s KEV catalog. The vector is an HTTP request sent over the network to the vulnerable component. A privileged attacker that gains network access can leverage the flaw to gain control of the system.

Generated by OpenCVE AI on August 4, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or upgrade to a fixed version provided by Oracle
  • Restrict network access to the PeopleSoft Enterprise FIN Billing Argentina system by limiting HTTP traffic to trusted internal networks or applying firewall rules
  • Ensure that the application is accessed over HTTPS only and disable unneeded HTTP endpoints; monitor for suspicious activity

Generated by OpenCVE AI on August 4, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Access Exploit Compromises Oracle PeopleSoft Enterprise FIN Billing Argentina

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Exploit Leading to Full Compromise of PeopleSoft Enterprise FIN Billing Argentina

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Exploit Leading to Full Compromise of PeopleSoft Enterprise FIN Billing Argentina

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Billing Argentina. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Billing Argentina. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Billing Argentina
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_billing_argentina:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Billing Argentina
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Billing Argentina
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:17:45.204Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61068

cve-icon Vulnrichment

Updated: 2026-07-24T14:17:39.297Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:37.533

Modified: 2026-08-04T17:56:07.283

Link: CVE-2026-61068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses