Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1 allows an attacker who already holds high‑privilege credentials and can reach the application over the network using T3 or IIOP protocols to compromise the system. Successful exploitation results in full takeover of the application, jeopardizing confidentiality, integrity, and availability. The CVSS vector indicates low attack complexity and no user interaction, but requires high privileges, confirming that the flaw is effectively a privilege‑escalation or improper access‑control weakness.

Affected Systems

Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1 is the only publicly identified affected version. No other versions or components are listed as vulnerable in the available data.

Risk and Exploitability

With a CVSS base score of 7.2, the vulnerability falls into the high‑severity range. The EPSS score of 0.00465 indicates a very low exploitation probability, meaning the current likelihood of attack is low; however, the network‑exposed nature and requirement for high‑privilege access suggest that only internal or compromised accounts could trigger the attack. The vulnerability is not yet in the CISA KEV catalog, indicating that no widespread exploitation has been documented, but the risk remains significant for organizations that have not applied the vendor patch.

Generated by OpenCVE AI on August 21, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft security patch released in August 2026 (see Oracle Security Alert August 2026).
  • Block or restrict T3 and IIOP traffic to the PeopleSoft instance using firewall rules or security group settings, allowing access only from trusted internal hosts.
  • Audit your user accounts and reduce the number of high‑privilege credentials, enforcing least‑privilege principles until the patch is applied.
  • Enable comprehensive logging and monitor T3 and IIOP connections for unauthorized login attempts, and investigate any anomalies promptly.

Generated by OpenCVE AI on August 21, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via T3/IIOP in Oracle PeopleSoft FIN Common Objects Brazil 9.1

Fri, 21 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Leading to Full Compromise via Network Access in Oracle PeopleSoft Enterprise FIN Common Objects Brazil
Weaknesses CWE-269

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Leading to Full Compromise via Network Access in Oracle PeopleSoft Enterprise FIN Common Objects Brazil
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects Brazil
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:23.385Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70861

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:20.801Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:17:42.243

Modified: 2026-08-21T04:18:14.967

Link: CVE-2026-70861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T07:00:12Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function