Junglewise Threat Intelligence

CVE-2026-61240: Oracle PeopleSoft Enterprise FIN Common Objects Argentina insecure access in eSettlements

CVE-2026-61240 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise FIN Common Objects Argentina. Vendors: Oracle.

Executive brief

A vulnerability exists in the eSettlements component of Oracle PeopleSoft's financial software for Argentina. An attacker with access to the local network can gain unauthorized access to sensitive financial data and potentially modify or delete records. This could lead to significant data breaches and disruption of financial settlement processes.

Technical details

This vulnerability affects the eSettlements component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1. It is characterized by an 'Adjacent' attack vector, meaning an attacker must be on the same physical or logical network segment as the target hardware. The exploit does not require authentication or user interaction. A successful attack results in a 'Scope Change' (S:C), indicating the impact can extend beyond the immediate component to other parts of the PeopleSoft environment. Attackers can achieve high confidentiality impact (full access to data) and low integrity impact (unauthorized modification of some data). Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats