Junglewise Threat Intelligence

CVE-2026-61057: Oracle PeopleSoft Enterprise FIN eSettlements data manipulation vulnerability

CVE-2026-61057 · Severity: medium · CVSS 4.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise FIN eSettlements, a tool used by organizations to manage electronic invoicing and payment processing, contains a security vulnerability. An unauthenticated attacker could potentially access, modify, or delete a subset of financial data over the network. While the vulnerability is difficult to exploit, it poses a risk to the integrity and confidentiality of financial records and settlement information.

Technical details

A vulnerability exists in the eSettlements component of Oracle PeopleSoft Enterprise FIN version 9.2. The flaw allows an unauthenticated attacker to gain unauthorized read, update, insert, or delete access to a subset of data via the HTTP protocol. The attack complexity is rated as high, suggesting that successful exploitation may require specific environmental conditions or significant effort to bypass existing security controls. The vulnerability impacts both confidentiality and integrity but does not affect system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN eSettlements 9.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats