Junglewise Threat Intelligence

CVE-2026-61238: Oracle PeopleSoft Enterprise FIN Common Objects Argentina data compromise in eProcurement

CVE-2026-61238 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Argentina. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise FIN Common Objects Argentina, a suite used for financial management and procurement, contains a critical security vulnerability in its eProcurement component. An unauthorized attacker can exploit this flaw over the network without needing a username or password. Successful exploitation could allow an attacker to view, modify, or delete sensitive financial and procurement data, potentially leading to significant financial fraud or operational disruption.

Technical details

A vulnerability exists in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina, specifically affecting version 9.1. The flaw is classified as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack does not require user interaction or elevated privileges. Successful exploitation grants the attacker unauthorized access to critical data, including the ability to create, delete, or modify all accessible data within the component. The CVSS 3.1 base score is 9.1, reflecting high impacts on confidentiality and integrity, though availability is not directly affected. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed

References

Related threats