Junglewise Threat Intelligence

CVE-2026-61233: Oracle PeopleSoft Enterprise FIN Common Objects Brazil takeover via Integration component

CVE-2026-61233 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Brazil. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle PeopleSoft's financial management software for Brazil, specifically within its integration components. This flaw allows an unauthorized person to gain full control over the system remotely over the internet without needing a username or password. An exploit could lead to a total compromise of financial data, unauthorized transactions, and a complete shutdown of the affected business processes.

Technical details

A vulnerability exists in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1. The flaw is characterized by its ease of exploitation, requiring no authentication or user interaction. An attacker can exploit this vulnerability over the network via HTTP. Successful exploitation grants the attacker full control over the affected component, impacting confidentiality, integrity, and availability (CVSS 9.8). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle and NVD publication.
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats