Description
Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil executes to compromise PeopleSoft Enterprise FIN Engineering Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Engineering Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation leading to Full System Takeover
Action: Apply Patch Immediately
AI Analysis

Impact

A low‑privileged attacker who has gained a login to the infrastructure on which Oracle PeopleSoft Enterprise FIN Engineering Brazil runs can exploit a flaw that does not require user interaction. The vulnerability permits the attacker to raise privileges locally, ultimately allowing complete takeover of the application and its data. This is a classic privilege‑management weakness (CWE‑269) that directly compromises confidentiality, integrity, and availability.

Affected Systems

Only Oracle’s PeopleSoft Enterprise FIN Engineering Brazil version 9.1 is listed as affected. No other products or versions are reported to be impacted.

Risk and Exploitability

The CVSS 3.1 base score of 7.8, combined with low attack complexity and low privilege prerequisites, means the attacker must be present on the same host but needs no additional credentials. The EPSS score of less than 1 % indicates very low current exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog, though that does not diminish the potential severity if a local user becomes compromised. Successful exploitation would grant the attacker full control over the application and any data it manages.

Generated by OpenCVE AI on September 18, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Acquire the latest Oracle PeopleSoft Enterprise FIN Engineering Brazil 9.1 security update and deploy it as soon as possible.
  • Minimize local user privileges by removing or disabling unnecessary service accounts that run the application.
  • Enforce strict application‑level access controls, validate all inputs, and audit logs for anomalous activity.

Generated by OpenCVE AI on September 18, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full System Takeover in PeopleSoft Enterprise FIN Engineering Brazil

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full System Takeover in PeopleSoft Enterprise FIN Engineering Brazil
Weaknesses CWE-269

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil executes to compromise PeopleSoft Enterprise FIN Engineering Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Engineering Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Engineering Brazil
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_engineering_brazil:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Engineering Brazil
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Engineering Brazil
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T12:50:10.089Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83420

cve-icon Vulnrichment

Updated: 2026-09-17T12:49:56.927Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:50.463

Modified: 2026-09-17T13:16:49.540

Link: CVE-2026-83420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T01:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management