Junglewise Threat Intelligence

CVE-2026-71112: Oracle PeopleSoft Enterprise FIN Common Objects authentication bypass

CVE-2026-71112 · Severity: high · CVSS 8.1 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise FIN Common Objects is a financial management module used by large enterprises to handle accounting, budgeting, and financial operations. This vulnerability allows an unauthenticated attacker over the network to gain complete control of the system through an HTTP-based exploit, potentially leading to unauthorized access to sensitive financial data, transaction manipulation, and service disruption.

Technical details

This is a difficult-to-exploit authentication bypass vulnerability in the Security component of PeopleSoft Enterprise FIN Common Objects. The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the affected system without authentication. Successful exploitation results in complete system compromise, including confidentiality, integrity, and availability impacts. PeopleSoft Enterprise FIN Common Objects version 9.2 is confirmed affected. No information on patch availability is currently available from the provided sources.

Affected products

  • Oracle PeopleSoft Enterprise FIN Common Objects 9.2

Timeline

  • 2026-08-18: disclosed

References

Related threats