Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication bypass (CWE-284) in the PeopleSoft Enterprise FIN Common Objects Brazil component. An unauthenticated attacker with HTTP network access can exploit this flaw to read any data stored in the affected system. Because confidentiality is the only impacted asset metric, the flaw enables attackers to gain unrestricted access to sensitive business information without needing valid credentials.

Affected Systems

Affected systems are Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1. Only the Brazil localized edition of the PeopleSoft suite is impacted. The vulnerability exists in the Common Objects component and applies to installations that have not applied the July 2026 patch.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates high risk with a non‑privileged, network‑based attack requiring low effort. The EPSS score of less than 1 % suggests that, at present, exploitation is considered unlikely, and the issue is not listed in the CISA KEV catalog. Nonetheless, because the flaw allows full data disclosure, an attacker exploiting it could potentially compromise business confidentiality and adversely affect operations, especially if other systems rely on the same data store.

Generated by OpenCVE AI on August 4, 2026 at 01:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch released in the July 2026 CPU for PeopleSoft Enterprise FIN Common Objects Brazil v9.1.
  • If immediate patching is infeasible, block HTTP traffic to the affected application from untrusted networks or enforce a VPN or firewall rule that limits access to authenticated users only.
  • Verify that proper access‑control logic is in place and that the application does not expose data to unauthenticated users, ensuring that the Common Objects component is correctly configured after any patch deployment.
  • Monitor audit logs for any anomalous access attempts to the Finance Common Objects module and investigate suspicious connections promptly.

Generated by OpenCVE AI on August 4, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Disclosure via Common Objects Authentication Bypass in PeopleSoft Enterprise FIN Common Objects Brazil

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Disclosure via Common Objects Authentication Bypass in PeopleSoft Enterprise FIN Common Objects Brazil

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Data Disclosure in Oracle PeopleSoft FIN Common Objects Brazil v9.1

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Data Disclosure in Oracle PeopleSoft FIN Common Objects Brazil v9.1

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:21:26.710Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61232

cve-icon Vulnrichment

Updated: 2026-07-22T19:21:23.529Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses