Executive brief
A vulnerability exists in Oracle's PeopleSoft Enterprise financial software specifically within the General Ledger component for Argentina. A user with low-level access to the system could potentially modify, delete, or create critical financial data, which could lead to inaccurate financial reporting or business disruption. Additionally, an attacker could cause a partial service outage, impacting the availability of the accounting system.
Technical details
This vulnerability affects Oracle PeopleSoft Enterprise FIN General Ledger Argentina version 9.1. It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have low-privileged user credentials and network access via HTTP. If successfully exploited, an attacker can achieve unauthorized creation, deletion, or modification of critical data within the General Ledger component. The exploit can also result in a partial denial of service (DoS), impacting the availability of the application. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN General Ledger Argentina 9.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published