Executive brief
A vulnerability exists in the Purchasing component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil. This software is used by organizations to manage financial operations and procurement specifically for the Brazilian market. An attacker could exploit this flaw over the network without needing a username or password to gain unauthorized access to sensitive business data, potentially compromising the confidentiality of financial records.
Technical details
A vulnerability in the Purchasing component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil (version 9.1) allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit is characterized as 'easily exploitable' and does not require user interaction. Successful exploitation results in a high confidentiality impact, allowing the attacker to gain unauthorized access to critical data or all accessible data within the affected component. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-61073 was published to the NVD.