Executive brief
Oracle PeopleSoft Enterprise FIN Common Objects Argentina, a financial management suite, contains a critical vulnerability in its Integration component. An unauthenticated attacker can exploit this over the network to gain full access to sensitive financial data and potentially modify or delete records. This flaw is particularly severe because it allows an attacker to pivot and impact other connected systems beyond the initial PeopleSoft environment.
Technical details
A critical vulnerability exists in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina version 9.1. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. The vulnerability is characterized by a 'Scope Change' (CVSS S:C), meaning an exploit can impact components beyond the security scope of the affected product. Attackers can achieve unauthorized access to all accessible data (High Confidentiality impact), perform unauthorized updates or deletions (Low Integrity impact), and cause a partial denial of service (Low Availability impact). Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed: NVD published the CVE record.