Executive brief
Oracle PeopleSoft Enterprise FIN Manufacturing Argentina, a software suite used for managing manufacturing operations and financial data, contains a critical security vulnerability. An unauthorized attacker can exploit this flaw over the network to gain full access to sensitive business data. This could result in the theft, deletion, or unauthorized modification of critical organizational information, potentially disrupting manufacturing operations and compromising financial integrity.
Technical details
A vulnerability in the Manufacturing component of Oracle PeopleSoft Enterprise FIN Manufacturing Argentina (version 9.1) allows for an unauthenticated compromise via HTTP. The flaw is characterized by low attack complexity and requires no user interaction or special privileges. Successful exploitation grants the attacker the ability to perform unauthorized creation, deletion, or modification of all accessible data, as well as complete unauthorized read access. The CVSS 3.1 score of 9.1 reflects high impacts to confidentiality and integrity, though availability is not directly cited as impacted by the base vector. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise FIN Manufacturing Argentina 9.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory