Junglewise Threat Intelligence

CVE-2026-61234: Oracle PeopleSoft Enterprise FIN Common Objects Brazil vulnerability in eProcurement

CVE-2026-61234 · Severity: high · CVSS 7.4 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Brazil. Vendors: Oracle.

Executive brief

A vulnerability exists in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil. This software is used by organizations to manage financial procurement processes. An attacker could exploit this flaw to gain unauthorized access to sensitive financial data or modify critical records, potentially leading to financial fraud or significant operational disruption.

Technical details

This vulnerability affects the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil, specifically version 9.1. It is classified as a high-complexity vulnerability (AC:H) that can be exploited by an unauthenticated attacker with network access via HTTP. While the specific vulnerability class (e.g., SQLi, XSS) is not explicitly named in the advisory, the impact is high for both confidentiality and integrity, allowing for the unauthorized creation, deletion, or modification of all accessible data within the component. The attack does not require user interaction or elevated privileges. Organizations are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats