Executive brief
A vulnerability exists in Oracle's PeopleSoft Enterprise FIN Engineering Argentina, a financial management software component used for engineering operations. A highly privileged attacker could exploit this flaw to gain unauthorized access to view, modify, or delete specific subsets of business data. While the impact on data integrity and confidentiality is limited, it could lead to unauthorized changes in financial or engineering records.
Technical details
A vulnerability in the Engineering component of Oracle PeopleSoft Enterprise FIN Engineering Argentina (version 9.1) allows for unauthorized data access and modification. The flaw is characterized by a high complexity of exploitation (AC:H) and requires the attacker to possess high-level administrative privileges (PR:H). An attacker with network access via HTTP can exploit this to read, update, insert, or delete a subset of data within the application. The vulnerability has been assigned a CVSS 3.1 base score of 3.3, reflecting limited impacts on confidentiality and integrity with no impact on availability. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle PeopleSoft Enterprise FIN Engineering Argentina 9.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.