Executive brief
A critical vulnerability exists in Oracle's PeopleSoft Enterprise FIN Manufacturing Brazil, a software suite used for managing financial and manufacturing operations. An attacker can remotely exploit this flaw over the network without needing any login credentials or user interaction. A successful attack allows for a complete takeover of the system, potentially leading to the theft of sensitive financial data, disruption of manufacturing processes, and total loss of system integrity.
Technical details
A vulnerability in the Integration component of Oracle PeopleSoft Enterprise FIN Manufacturing Brazil (version 9.1) allows for complete system compromise. The flaw is categorized as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTPS. Successful exploitation grants the attacker full control over the affected PeopleSoft instance, impacting confidentiality, integrity, and availability. While the specific CWE is not provided in the advisory, the CVSS score of 9.8 and the 'takeover' description suggest a critical flaw such as an authentication bypass or remote code execution. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise FIN Manufacturing Brazil 9.1
Timeline
- 2026-07-21: disclosed: Vulnerability published in Oracle Critical Patch Update and NVD.