Junglewise Threat Intelligence

CVE-2026-61232: Oracle PeopleSoft Enterprise FIN Common Objects Brazil data exposure

CVE-2026-61232 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Brazil. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise FIN Common Objects Brazil, a financial management component used for Brazilian business operations, contains a vulnerability that allows unauthorized data access. An attacker can exploit this over the network without needing a username or password. If successful, this could lead to the exposure of sensitive financial records or complete access to all data within the affected component.

Technical details

A vulnerability exists in the Common Objects component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to bypass confidentiality controls, resulting in unauthorized access to critical data or a complete compromise of all data accessible through the component. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no impact on integrity or availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats