Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw involves improper handling of authentication and authorization, which maps to weaknesses such as information exposure, insufficient privilege checks, weak authentication controls, and lack of proper access restrictions. Successful exploitation results in complete takeover of the application, providing an attacker full control over confidential data, system integrity, and availability.

Affected Systems

Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1 is affected. No other product versions are listed as vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 9.8 marks this vulnerability as critical, while the EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the weakness via unauthenticated HTTP traffic to the exposed Integration endpoint, making the attack path straightforward for anyone with network reach to the target server.

Generated by OpenCVE AI on August 4, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade to a fixed version of PeopleSoft Enterprise FIN Common Objects Brazil.
  • Configure network controls to restrict HTTP access to trusted hosts, for example by firewalling or applying IP whitelisting to the PeopleSoft web services.
  • Enforce proper authentication and authorization settings in the application configuration to eliminate unauthenticated entry points.

Generated by OpenCVE AI on August 4, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Integration Component Exploit Enables Full Application Takeover

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Full Compromise of Oracle PeopleSoft FIN Common Objects Brazil via Unauthenticated HTTP Access

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Full Compromise of Oracle PeopleSoft FIN Common Objects Brazil via Unauthenticated HTTP Access

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:20:52.161Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61233

cve-icon Vulnrichment

Updated: 2026-07-22T19:20:47.779Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function