Description
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise FIN Manufacturing Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Manufacturing Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw in the Integration component of Oracle PeopleSoft Enterprise FIN Manufacturing Brazil allows an unauthenticated attacker to connect via HTTPS and fully compromise the application. The vulnerability stems from a failure to enforce authentication and missing access control, resulting in complete takeover. Exploitation would grant an attacker control over all business processes and expose sensitive financial data, with severe impacts on confidentiality, integrity, and availability.

Affected Systems

Oracle PeopleSoft Enterprise FIN Manufacturing Brazil version 9.1 is the only affected release. The vulnerability specifically references the Integration component, so deployments that include this component are at risk. No other versions or components are identified as impacted.

Risk and Exploitability

The CVSS base score of 9.8 denotes critical risk, while the EPSS score of less than 1 % indicates a low probability of current exploitation. The attack can be carried out with no authentication from any machine that can reach the product’s HTTPS interface. The vulnerability is not listed in the CISA KEV catalog, but the high severity remains a significant concern. If exploited, the attacker would achieve complete control, jeopardizing all finance and manufacturing operations.

Generated by OpenCVE AI on August 4, 2026 at 01:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 security patch for PeopleSoft Enterprise FIN Manufacturing Brazil
  • Restrict HTTPS access to trusted IP ranges or implement VPN/Firewall controls to limit exposure
  • Enable comprehensive monitoring and logging of HTTPS traffic to detect anomalous activity and potential exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Enables Full Compromise of Oracle PeopleSoft Manufacturing Finance Application

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Enables Full Compromise of Oracle PeopleSoft Manufacturing Finance Application

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTPS in Oracle PeopleSoft Enterprise FIN Manufacturing Brazil

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTPS in Oracle PeopleSoft Enterprise FIN Manufacturing Brazil

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise FIN Manufacturing Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Manufacturing Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Manufacturing Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_manufacturing_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Manufacturing Brazil
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Manufacturing Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:34:08.784Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61245

cve-icon Vulnrichment

Updated: 2026-07-22T18:33:59.098Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function