Junglewise Threat Intelligence

CVE-2026-61087: Oracle PeopleSoft Enterprise FIN Payables information disclosure in Security component

CVE-2026-61087 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise FIN Payables, a software suite used by organizations to manage financial accounts payable and vendor payments, contains a security vulnerability. An unauthorized person can access the system over the network without needing a username or password. This could lead to the exposure of sensitive financial records or a complete breach of all data managed within the Payables module.

Technical details

A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise FIN Payables version 9.2. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to bypass security controls to gain unauthorized access to critical data or achieve complete read access to all data within the FIN Payables module. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no impact on integrity or availability. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Payables 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References