Description
Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Payables. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Payables accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PeopleSoft Enterprise FIN Payables 9.2 contains a flaw in its security component that permits an unauthenticated attacker with network access via HTTP to read sensitive financial data without providing credentials. This vulnerability, identified as CWE‑284, allows a compromise of data confidentiality only, as the attack path does not expose integrity or availability weaknesses. The vulnerability manifests by bypassing normal access control checks, enabling the attacker to retrieve any data the application is authorized to serve to a logged‑in user.

Affected Systems

Oracle PeopleSoft Enterprise FIN Payables version 9.2 is affected by this flaw. The product is part of Oracle’s PeopleSoft suite used primarily for financial transaction processing.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 reflects a significant confidentiality impact; the EPSS score of less than 1% indicates a low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated HTTP connection to the exposed interface; this inference is drawn from the statement that an attacker with network access via HTTP can exploit the vulnerability, implying that any user who can reach the PeopleSoft web server could potentially read sensitive data if the patch is not applied.

Generated by OpenCVE AI on August 4, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch for Oracle PeopleSoft Enterprise FIN Payables 9.2 as detailed in the Oracle advisory linked above.
  • If patch deployment is delayed, block or restrict external HTTP traffic to the PeopleSoft instance using firewall rules or enforce VPN access to ensure only authorized internal users can reach the service.
  • Enable logging of all access attempts to the PeopleSoft application and regularly review logs to detect any unauthenticated or suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise FIN Payables 9.2 Vulnerability allows unauthenticated remote access to confidential financial data.

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise FIN Payables 9.2 Vulnerability allows unauthenticated remote access to confidential financial data.

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exposure in Oracle PeopleSoft Enterprise FIN Payables 9.2
Weaknesses CWE-200
CWE-287

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exposure in Oracle PeopleSoft Enterprise FIN Payables 9.2
Weaknesses CWE-200
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Payables. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Payables accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Payables
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_payables:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Payables
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Payables
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:12:33.607Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61087

cve-icon Vulnrichment

Updated: 2026-07-23T19:12:20.017Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses