Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the Staffing component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina allows an attacker who can reach the application over HTTP to compromise the system. The vulnerability is described as easily exploitable, enabling a low‑privileged attacker to achieve full takeover of the product. A successful exploit would allow the adversary to read, modify, and delete data as well as execute arbitrary code, resulting in complete loss of confidentiality, integrity, and availability.

Affected Systems

Oracle PeopleSoft distributes the affected product as PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1. No other Oracle products are specifically listed as impacted, but the description indicates that a successful attack may broaden the scope to other modules that share the same environment.

Risk and Exploitability

The attack vector is a remote HTTP request from a low‑privileged attacker on the network. The CVSS 3.1 Base Score of 9.9 demonstrates critical impact, while the EPSS score of less than 1% indicates that exploitation is not yet widespread. The weakness stems from improper access control (CWE-284), enabling the attacker to cross from a restricted user context to full system control, potentially impacting additional PeopleSoft components.

Generated by OpenCVE AI on August 4, 2026 at 16:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU July 2026 advisory, which addresses the improper access control flaw (CWE-284).
  • Restrict public HTTP access to PeopleSoft by configuring firewall rules or network segmentation, limiting traffic to trusted internal hosts only.
  • Conduct an access‑control audit of all PeopleSoft accounts, disabling unnecessary low‑privileged accounts and enforcing the principle of least privilege.

Generated by OpenCVE AI on August 4, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Oracle PeopleSoft Improper Access Control Enables Remote Takeover

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Oracle PeopleSoft Improper Access Control Enables Remote Takeover

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Low‑Privileged HTTP Access in Oracle PeopleSoft Enterprise FIN Common Objects Argentina

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Low‑Privileged HTTP Access in Oracle PeopleSoft Enterprise FIN Common Objects Argentina

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Argentina
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_argentina:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Argentina
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Argentina
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:20:25.177Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61242

cve-icon Vulnrichment

Updated: 2026-07-22T18:20:21.656Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses