Executive brief
A vulnerability in the Billing component of Oracle PeopleSoft Enterprise FIN Billing Argentina could allow an authorized user with high-level privileges to take full control of the system. PeopleSoft Enterprise FIN is used by organizations to manage financial operations, including invoicing and billing processes. A successful exploit could lead to a total compromise of the application, potentially resulting in the theft of sensitive financial data, unauthorized modification of records, or a complete service outage.
Technical details
A vulnerability in the Billing component of Oracle PeopleSoft Enterprise FIN Billing Argentina (version 9.1) allows a high-privileged attacker with network access via HTTP to compromise the application. While the specific CWE is not identified in the advisory, the impact is rated for full loss of Confidentiality, Integrity, and Availability (takeover). The attack vector is network-based and requires high privileges, but no user interaction is necessary for successful exploitation. This issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN Billing Argentina 9.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory