Junglewise Threat Intelligence

CVE-2026-61062: Oracle PeopleSoft Enterprise FIN Cash Management takeover via local exploit

CVE-2026-61062 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise FIN Cash Management, a tool used by organizations to manage liquidity and financial operations, contains a high-severity vulnerability. A low-privileged user with existing access to the underlying server can exploit this flaw to take full control of the application. This could lead to the theft of sensitive financial data, disruption of cash management operations, and potential unauthorized access to other connected systems.

Technical details

A vulnerability exists in the Cash Management component of Oracle PeopleSoft Enterprise FIN Cash Management version 9.2. The flaw is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure where the software executes. Successful exploitation results in a complete takeover of the PeopleSoft Enterprise FIN Cash Management application and carries a 'scope change' (S:C), meaning the impact can extend to other products or the underlying host environment. The vulnerability affects confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Cash Management 9.2

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-61062 was published to the NVD.

References

Related threats