Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1 allows an unauthenticated attacker to send crafted HTTP requests that bypass authentication checks (CWE‑287) and gain unauthorized access to privileged functions (CWE‑284). The flaw also reveals a privilege misconfiguration (CWE‑306) that threatens confidentiality, integrity, and availability. Successful exploitation leads to full takeover of the PeopleSoft instance, enabling the attacker to read, modify, or delete data and disrupt normal operations.

Affected Systems

Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1, specifically the eProcurement component, is affected. The vulnerability is present only in the 9.1 release of the Brazil‑centric common objects package.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 signals high severity across all impact submetrics. EPSS is reported as <1%, indicating a low current exploitation rate, and the flaw is not in CISA's KEV catalog. Per the description, the attacker requires only network access to the HTTP endpoint—no credentials or elevated privileges are needed. The likely attack vector is over the public or corporate network, and the vulnerability can be exercised by any remote party able to reach the vulnerable URL.

Generated by OpenCVE AI on August 4, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security advisories for updates or patches relevant to this vulnerability.
  • Restrict inbound HTTP traffic to the PeopleSoft application to trusted IP addresses or enforce VPN access to limit exposure.
  • Enable comprehensive logging and monitoring of web requests to detect anomalous patterns and potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Bypass Leads to Full Application Takeover in Oracle PeopleSoft

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Application Takeover in Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Application Takeover in Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:10:41.312Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61074

cve-icon Vulnrichment

Updated: 2026-07-24T14:09:55.746Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function