Description
Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease Administration executes to compromise PeopleSoft Enterprise FIN Lease Administration. While the vulnerability is in PeopleSoft Enterprise FIN Lease Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Lease Administration accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Lease Administration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle PeopleSoft Enterprise FIN Lease Administration 9.2 allows an attacker who can log on to the underlying infrastructure to create, delete or modify data and gain unauthorized access to all accessible PeopleSoft data. The flaw permits low‑privileged users to bypass normal access controls, resulting in confidentiality and integrity violations that may affect all data stored in the Lease Administration module. The weakness is a Weak Access Control flaw (CWE‑284).

Affected Systems

Affected vendor and product are Oracle Corporation’s PeopleSoft Enterprise FIN Lease Administration version 9.2. No other versions are listed as affected. The vulnerability originates in the Lease Administration component, and Oracle’s security advisory references this single product and version, with no additional product mappings in the CPE list.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high severity vulnerability when accounting for confidentiality and integrity impacts. Given the local attack vector, the vulnerability is exploitable by anyone who can log on to the system with low privileges, and because the scope is changed, exploitation can affect a broader set of data than originally intended. The EPSS score of 0.00088 (≈0.088%) indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV, but the potential for significant data loss remains high. Exfiltration or data tampering may occur without user interaction.

Generated by OpenCVE AI on August 20, 2026 at 19:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for PeopleSoft Enterprise FIN Lease Administration 9.2 as outlined in the August 2026 security advisory.
  • Restrict local logon privileges and enforce least privilege on user accounts that have access to the PeopleSoft environment.
  • Implement network segmentation and restrict direct access to the PeopleSoft application servers from untrusted networks.
  • Monitor audit logs for unauthorized create/delete/modify activity and set up alerts on critical data changes.

Generated by OpenCVE AI on August 20, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification Vulnerability in Oracle PeopleSoft Enterprise FIN Lease Administration 9.2

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle PeopleSoft Enterprise FIN Lease Administration 9.2
Weaknesses CWE-732

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle PeopleSoft Enterprise FIN Lease Administration 9.2
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease Administration executes to compromise PeopleSoft Enterprise FIN Lease Administration. While the vulnerability is in PeopleSoft Enterprise FIN Lease Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Lease Administration accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Lease Administration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Lease Administration
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_lease_administration:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Lease Administration
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Lease Administration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:02:09.135Z

Reserved: 2026-08-04T22:06:34.616Z

Link: CVE-2026-71092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:18:09.450

Modified: 2026-08-20T13:08:14.613

Link: CVE-2026-71092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:15:04Z

Weaknesses