Description
Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering Argentina. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Engineering Argentina accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Engineering Argentina accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle PeopleSoft Enterprise FIN Engineering Argentina 9.1 allows a high‑privileged attacker with network access via HTTP to perform unauthorized update, insert or delete operations, as well as read sensitive data. The flaw is an improper access control weakness (CWE‑284) that compromises the integrity and confidentiality of the application’s data.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise FIN Engineering Argentina version 9.1 is affected by this issue.

Risk and Exploitability

The CVSS score of 3.3 indicates a low to moderate risk level, and the EPSS score of less than 1% suggests that this vulnerability is unlikely to be actively exploited. However, because it requires a high‑privileged attacker who can reach the system over HTTP and permits data modification and disclosure, it remains a concern for organizations that operate the affected PeopleSoft instance.

Generated by OpenCVE AI on August 4, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU July 2026 advisory to address the improper access control flaw in PeopleSoft Enterprise FIN Engineering Argentina 9.1.
  • Limit the use of high‑privileged accounts by enforcing role‑based access controls and removing unnecessary elevated rights.
  • Restrict external HTTP access to the PeopleSoft application and monitor logs for anomalous access attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle PeopleSoft Enterprise FIN Engineering Argentina 9.1

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via HTTP in Oracle PeopleSoft Enterprise FIN Engineering Argentina

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via HTTP in Oracle PeopleSoft Enterprise FIN Engineering Argentina

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering Argentina. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Engineering Argentina accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Engineering Argentina accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Engineering Argentina
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_engineering_argentina:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Engineering Argentina
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Engineering Argentina
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:16:10.628Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61071

cve-icon Vulnrichment

Updated: 2026-07-24T14:16:06.244Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:37.873

Modified: 2026-08-06T15:02:17.457

Link: CVE-2026-61071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses