Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle PeopleSoft's Enterprise FIN Common Objects Brazil component; specifically, the Staffing module allows an unauthenticated attacker who can reach the service over HTTP to read or retrieve any data stored in the application. The flaw is an improper access control (CWE-284) and provides a confidentiality impact without affecting integrity or availability. Its CVSS 3.1 Base Score of 7.5 indicates a significant potential for data disclosure.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise FIN Common Objects Brazil product, version 9.1, is the only affected system. Administrators and users should check that this version is running and consider applying available fixes.

Risk and Exploitability

Because the flaw is triggerable by any host that can establish an HTTP connection to the system and requires no credentials, the attack vector is straightforward and the risk is considerable. The EPSS score is below 1 %, suggesting that active exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high confidentiality impact and ease of exploitation warrant immediate remediation.

Generated by OpenCVE AI on August 4, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade released for PeopleSoft Enterprise FIN Common Objects Brazil 9.1 as detailed in the Oracle CPU July 2026 advisory.
  • Restrict inbound HTTP traffic to the PeopleSoft instance to trusted networks or enforce VPN access so that only authorized users can reach the endpoint.
  • Implement monitoring and alerting for unexpected unauthenticated HTTP requests to the Staffing component, and review logs for signs of data exfiltration.

Generated by OpenCVE AI on August 4, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in PeopleSoft Enterprise FIN Common Objects Brazil

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in PeopleSoft Enterprise FIN Common Objects Brazil

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Data Bypass in Oracle PeopleSoft FIN Common Objects Brazil

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Data Bypass in Oracle PeopleSoft FIN Common Objects Brazil

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:17:26.070Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61236

cve-icon Vulnrichment

Updated: 2026-07-22T19:17:21.223Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses