Description
Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General Ledger Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN General Ledger Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN General Ledger Argentina. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle PeopleSoft Enterprise FIN General Ledger Argentina stems from insufficient authorization checks in the General Ledger module. A low‑privilege attacker who can reach the application over HTTP can craft requests that bypass normal role restrictions, enabling unauthorized creation, deletion, or modification of critical ledger records. The flaw also permits a partial denial of service by rendering the application unresponsive to legitimate users. Because confidentiality is not affected, the primary impacts are on data integrity and availability, undermining accounting processes and regulatory compliance.

Affected Systems

This issue affects Oracle PeopleSoft Enterprise FIN General Ledger Argentina version 9.1, specifically the General Ledger component exposed through the HTTP interface. Any installation that hosts the General Ledger portal over HTTP and runs the 9.1 release is vulnerable. The advisory lists only version 9.1 as affected; later releases may contain fixes but are not known to be impacted.

Risk and Exploitability

The CVSS base score of 5.9 indicates moderate severity, with high integrity and low availability impact. The EPSS score of < 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not included in CISA’s KEV catalog. Nonetheless, the attack vector is network (HTTP), requiring only low user privileges and no user interaction. If exploited, the attacker can damage ledger accuracy and impede business operations, but no known exploits have been publicly documented.

Generated by OpenCVE AI on August 2, 2026 at 20:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle patch or update that addresses the authorization bypass flaw in the General Ledger component as outlined in Oracle’s July 2026 CPU alert.
  • Restrict external HTTP access to the PeopleSoft application and enforce multi‑factor authentication for low‑privilege accounts.
  • Enforce strict role‑based access controls to guarantee that only authorized users can create, delete, or modify ledger data.
  • Enable detailed request logging and monitor for anomalous activity, such as repeated unauthorized modification attempts, and configure alerts.

Generated by OpenCVE AI on August 2, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title PeopleSoft General Ledger Authorization Bypass Enables Unauthorized Data Modification

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in PeopleSoft Enterprise FIN General Ledger Argentina
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in PeopleSoft Enterprise FIN General Ledger Argentina
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General Ledger Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN General Ledger Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN General Ledger Argentina. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin General Ledger Argentina
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_general_ledger_argentina:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin General Ledger Argentina
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Peoplesoft Enterprise Fin General Ledger Argentina
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:16:59.904Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61069

cve-icon Vulnrichment

Updated: 2026-07-24T14:16:48.639Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses