Junglewise Threat Intelligence

CVE-2026-61239: Oracle PeopleSoft Enterprise FIN Common Objects Argentina compromise in eProcurement

CVE-2026-61239 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Argentina. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina. This software is used by organizations to manage financial operations and procurement processes. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive financial data, modify or delete critical records, and potentially disrupt business operations. The impact may also extend to other integrated Oracle products.

Technical details

This vulnerability affects the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina, specifically version 9.1. It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). The flaw allows an attacker to gain unauthorized read, write, and delete access to critical data. Notably, the vulnerability involves a scope change (S:C), meaning a successful exploit can impact security components beyond the immediate PeopleSoft environment. It also allows for a partial denial of service. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1

Timeline

  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: Vulnerability published in the NVD.

References

Related threats