Executive brief
A vulnerability exists in Oracle PeopleSoft's financial project management software that could allow an attacker to take full control of the application. To exploit this, an attacker must have access to the underlying server infrastructure and trick a legitimate user into performing a specific action. A successful attack could lead to the complete compromise of financial project data and system operations.
Technical details
This vulnerability affects the Projects component of Oracle PeopleSoft Enterprise FIN Project Costing version 9.2. It is classified as a local attack (AV:L) because it requires the attacker to have logon access to the infrastructure where the software executes. Although the attacker is unauthenticated (PR:N), the exploit requires human interaction (UI:R) from a legitimate user to succeed. If successfully exploited, the vulnerability allows for a complete compromise of confidentiality, integrity, and availability, potentially resulting in a full takeover of the PeopleSoft Enterprise FIN Project Costing environment. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN Project Costing 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.