Junglewise Threat Intelligence

CVE-2026-60601: Oracle PeopleSoft Enterprise FIN Common Objects integrity compromise in Security

CVE-2026-60601 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle PeopleSoft Enterprise FIN Common Objects, a suite used for financial management and business operations. A low-privileged user with access to the underlying system could potentially manipulate or delete critical financial data. Exploiting this issue is considered difficult as it requires the attacker to trick a legitimate user into performing a specific action.

Technical details

This vulnerability affects the Security component of Oracle PeopleSoft Enterprise FIN Common Objects version 9.2. It is classified as a local integrity impact issue (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N). An attacker with low-privileged access to the infrastructure where the software executes can compromise the system, provided they can successfully induce a legitimate user to interact with the exploit. The attack is characterized by high complexity and requires user interaction, but if successful, it allows for unauthorized creation, deletion, or modification of all accessible data within the FIN Common Objects module. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects 9.2

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats