Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Brazil accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the eProcurement module of Oracle PeopleSoft Enterprise FIN Common Objects Brazil. It permits an attacker who does not have valid credentials, as long as the host is reachable over HTTP, to create, delete, or modify critical data, or to gain unrestricted access to any data stored in the system. This is caused by an insufficient access control measure, identified CWE‑284, which leads to loss of confidentiality and integrity.

Affected Systems

Oracle PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1, is affected. The vulnerability specifically affects the eProcurement component. Any installation of this product that has not applied the July 2026 CPU update is susceptible.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 indicates a high threat level. The EPSS score of less than 1 % means that, at this time, active exploitation is unlikely, and the issue is not in the CISA KEV list. The attack vector is a public network via HTTP, unauthenticated, so any exposed PeopleSoft instance is at risk. Successful exploitation can result in unauthorized data alteration or full disclosure of all accessible information.

Generated by OpenCVE AI on August 4, 2026 at 16:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for PeopleSoft Enterprise FIN Common Objects Brazil 9.1 released in the July 2026 CPU update.
  • If the patch cannot be deployed immediately, block HTTP traffic to the eProcurement endpoint and restrict access to authenticated users only.
  • Implement network segmentation and firewall rules to limit external connectivity to the PeopleSoft environment, and monitor logs for suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enables Unauthorized Data Modification in Oracle PeopleSoft eProcurement

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enables Unauthorized Data Modification in Oracle PeopleSoft eProcurement

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification in Oracle PeopleSoft eProcurement for Brazil

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification in Oracle PeopleSoft eProcurement for Brazil

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Brazil accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:16:06.716Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61234

cve-icon Vulnrichment

Updated: 2026-07-22T19:16:02.733Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses