Executive brief
Oracle PeopleSoft Enterprise FIN Staffing Front Office, a tool used by organizations to manage recruitment and staffing operations, contains a security vulnerability. An unauthorized attacker could exploit this over the network to modify, create, or delete critical business data. This could lead to significant data integrity issues, such as the alteration of staffing records or financial information, without requiring any user interaction or login credentials.
Technical details
A vulnerability in the Staffing Front Office component of Oracle PeopleSoft Enterprise FIN version 9.2 allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is characterized by its ease of exploitability (low attack complexity) and requires no user interaction. While the vulnerability does not impact data confidentiality or system availability, it allows for high-impact unauthorized integrity changes, including the modification or deletion of all accessible data within the component. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN Staffing Front Office 9.2
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed