Executive brief
Oracle PeopleSoft Enterprise FIN Common Objects Argentina, a financial management suite used for business operations and staffing, contains a critical security vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive financial and staffing data, potentially disrupting business operations.
Technical details
A vulnerability exists in the Staffing component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina, specifically affecting version 9.1. The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability (CVSS 8.8). While the specific CWE is not provided in the advisory, the impact indicates a significant authorization or injection-related failure. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1
Timeline
- 2026-07-21: disclosed: Published by Oracle and NVD