Executive brief
A vulnerability exists in Oracle PeopleSoft Enterprise FIN Cash Management, a software suite used by organizations to manage financial liquidity and cash flows. An unauthenticated attacker could exploit this flaw over the network to gain full access to sensitive financial data, potentially allowing them to view, modify, or delete critical records. While the attack is difficult to execute, a successful breach could impact other integrated business systems and compromise the integrity of the organization's financial operations.
Technical details
A vulnerability in the Cash Management component of Oracle PeopleSoft Enterprise FIN Cash Management (version 9.2) allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is characterized by a high attack complexity, suggesting specific conditions or configurations must be met for successful exploitation. If exploited, the vulnerability results in a scope change (S:C), meaning the attacker can impact components beyond the immediate PeopleSoft environment. The impact includes complete unauthorized access to data (Confidentiality) and the ability to create, delete, or modify critical data (Integrity). The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN Cash Management 9.2
Timeline
- 2026-07-21: disclosed: Initial publication by Oracle and NVD
- 2026-07-21: advisory: Included in Oracle July 2026 Critical Patch Update