Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PeopleSoft Enterprise FIN Common Objects is a financial management application. A flaw in its Security component provides an access control weakness (CWE‑284) that lets attackers send unauthenticated HTTP requests to bypass authentication and permission checks. If exploited, an attacker can read, modify, or delete financial records and gain complete control over the application, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle PeopleSoft Enterprise FIN Common Objects version 9.2 is identified as vulnerable. No other versions are confirmed at this time. The flaw is reachable through the HTTP interface exposed by the application, targeting the Security component.

Risk and Exploitability

The base CVSS score of 8.1 signals high severity. An attacker requires network connectivity to the HTTP service and must craft a bypass request, which presents moderate to high effort. The EPSS score of less than 1% indicates a low probability of active exploitation, and the vulnerability is not listed in CISA KEV. However, because the flaw allows complete takeover, the potential impact remains significant and organizations should prioritize remediation.

Generated by OpenCVE AI on August 20, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade release that addresses the access control vulnerability in PeopleSoft Enterprise FIN Common Objects 9.2.
  • If a patch is not yet available, restrict HTTP access to the application by using firewall rules, VPN access, or network segmentation to allow only trusted internal networks to reach the service.
  • Enable detailed logging and monitor for unauthenticated HTTP requests or anomalous activity, and investigate any suspicious attempts promptly.

Generated by OpenCVE AI on August 20, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Allows Full Takeover of Oracle PeopleSoft Enterprise FIN Common Objects

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Allows Full Takeover of Oracle PeopleSoft Enterprise FIN Common Objects

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title PeopleSoft FIN Common Objects Authentication Bypass Enabling Full Application Takeover
Weaknesses CWE-269
CWE-287

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title PeopleSoft FIN Common Objects Authentication Bypass Enabling Full Application Takeover
Weaknesses CWE-269
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Common Objects
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Common Objects
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Common Objects
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:01:11.907Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:11.753

Modified: 2026-09-04T17:48:20.193

Link: CVE-2026-71112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:00:04Z

Weaknesses