Executive brief
Oracle PeopleSoft Enterprise FIN eSettlements is a financial management tool used by organizations to manage electronic invoicing and payment settlements. A vulnerability in this component allows a highly privileged user who already has access to the underlying server infrastructure to view sensitive data they are not authorized to see. While the risk is limited to internal users with high-level access, it could lead to the unauthorized disclosure of financial records.
Technical details
An information disclosure vulnerability exists in the eSettlements component of Oracle PeopleSoft Enterprise FIN version 9.2. The flaw is categorized as an improper access control issue that allows a high-privileged attacker with local logon access to the underlying infrastructure to compromise the application. Successful exploitation results in unauthorized read access to a subset of data managed by the eSettlements module. The attack vector is local, requiring the attacker to already possess significant permissions on the host system. Oracle addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise FIN eSettlements 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released