Executive brief
A critical vulnerability exists in Oracle PeopleSoft Enterprise FIN Expenses, a software suite used by organizations to manage financial expense reporting and processing. An unauthenticated attacker can remotely access the system over the network to view, modify, or delete sensitive financial data. This could lead to significant data breaches, fraudulent financial activity, and partial disruption of the expense management service.
Technical details
A vulnerability in the Expenses component of Oracle PeopleSoft Enterprise FIN Expenses (version 9.2) allows for remote compromise without authentication. The flaw is reachable via HTTP and is characterized by low attack complexity, requiring no user interaction. An attacker can achieve high confidentiality and integrity impacts, potentially gaining full access to all data within the FIN Expenses module, along with a low availability impact (partial DoS). While the specific CWE is not detailed in the advisory, the impact profile suggests a significant failure in access control or input validation within the web-facing component. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise FIN Expenses 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published