Junglewise Threat Intelligence

CVE-2026-61056: Oracle PeopleSoft Enterprise FIN Grants Data Manipulation in Grants

CVE-2026-61056 · Severity: medium · CVSS 4.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle PeopleSoft Enterprise FIN Grants, a software suite used by organizations to manage financial grant processes. An unauthenticated attacker could potentially access the system over the network to view, modify, or delete certain grant-related data. While the vulnerability is considered difficult to exploit, it could lead to unauthorized changes to financial records or the exposure of sensitive grant information.

Technical details

This vulnerability affects the Grants component of Oracle PeopleSoft Enterprise FIN Grants version 9.2. It is an unauthenticated, network-based vulnerability exploitable via HTTP. The attack complexity is rated as high, suggesting that successful exploitation requires specific conditions or significant effort beyond simple request sending. If exploited, an attacker can gain unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some data within the Grants module. The vulnerability does not appear to impact system availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Grants 9.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References