Impact
The vulnerability is an authentication bypass (CWE-284) in the PeopleSoft Enterprise FIN Common Objects Brazil component. An unauthenticated attacker with HTTP network access can exploit this flaw to read any data stored in the affected system. Because confidentiality is the only impacted asset metric, the flaw enables attackers to gain unrestricted access to sensitive business information without needing valid credentials.
Affected Systems
Affected systems are Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1. Only the Brazil localized edition of the PeopleSoft suite is impacted. The vulnerability exists in the Common Objects component and applies to installations that have not applied the July 2026 patch.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high risk with a non‑privileged, network‑based attack requiring low effort. The EPSS score of less than 1 % suggests that, at present, exploitation is considered unlikely, and the issue is not listed in the CISA KEV catalog. Nonetheless, because the flaw allows full data disclosure, an attacker exploiting it could potentially compromise business confidentiality and adversely affect operations, especially if other systems rely on the same data store.
OpenCVE Enrichment