Executive brief
A critical vulnerability exists in Oracle's PeopleSoft staffing software used for financial and front-office operations in Brazil. A user with low-level access to the corporate network can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive financial data, disruption of staffing operations, and potential unauthorized access to other connected business systems.
Technical details
A vulnerability in the Staffing component of Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil version 9.1 allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Notably, the vulnerability includes a 'scope change' (S:C), meaning a successful exploit can impact security components beyond the immediate PeopleSoft environment. The attack results in a total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil 9.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released