Impact
The flaw exists in the eProcurement module of Oracle PeopleSoft Enterprise FIN Common Objects Brazil. It permits an attacker who does not have valid credentials, as long as the host is reachable over HTTP, to create, delete, or modify critical data, or to gain unrestricted access to any data stored in the system. This is caused by an insufficient access control measure, identified CWE‑284, which leads to loss of confidentiality and integrity.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1, is affected. The vulnerability specifically affects the eProcurement component. Any installation of this product that has not applied the July 2026 CPU update is susceptible.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 indicates a high threat level. The EPSS score of less than 1 % means that, at this time, active exploitation is unlikely, and the issue is not in the CISA KEV list. The attack vector is a public network via HTTP, unauthenticated, so any exposed PeopleSoft instance is at risk. Successful exploitation can result in unauthorized data alteration or full disclosure of all accessible information.
OpenCVE Enrichment