Junglewise Threat Intelligence

CVE-2026-60595: Oracle PeopleSoft Enterprise FIN Pay/Bill Management Information Disclosure

CVE-2026-60595 · Severity: medium · CVSS 5.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability in Oracle's PeopleSoft Pay/Bill Management module could allow an employee or other user with low-level access to the system's underlying infrastructure to view sensitive financial data. This flaw could lead to the unauthorized disclosure of critical business information or complete access to all data managed by the Pay/Bill component. Organizations using version 9.2 of this software should apply the relevant security updates to prevent internal data breaches.

Technical details

An information disclosure vulnerability exists in the Paybill Management component of Oracle PeopleSoft Enterprise FIN Pay/Bill Management version 9.2. The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where the application executes. A successful exploit allows a low-privileged attacker to bypass confidentiality controls, potentially gaining full access to all data accessible by the Pay/Bill Management module. The vulnerability is addressed in the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise FIN Pay/Bill Management 9.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References