Junglewise Threat Intelligence

CVE-2026-61074: Oracle PeopleSoft Enterprise FIN Common Objects Brazil takeover in eProcurement

CVE-2026-61074 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Brazil. Vendors: Oracle.

Executive brief

A high-severity vulnerability has been identified in Oracle PeopleSoft's eProcurement component for Brazilian financial operations. This flaw could allow an unauthorized person to gain full control over the affected system via the internet. A successful attack could lead to a complete compromise of financial data, unauthorized transactions, and a total loss of system availability.

Technical details

This vulnerability exists in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil, specifically affecting version 9.1. It is characterized as a difficult-to-exploit flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. A successful exploit results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability (CVSS 8.1). The attack complexity is rated as high, suggesting specific conditions or configurations must be met for successful exploitation. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-61074 was published to the NVD.

References

Related threats