Sceawere

Vulnerability Detail

CVE-2026-61238Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft eProcurement Unauthorized Data Access

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Common Objects Argentina
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:54.687Z",
  "pubdate": "2026-07-21T22:18:54.687Z",
  "executiveSummary": "This vulnerability affects the Oracle PeopleSoft Enterprise FIN Common Objects Argentina product, specifically the eProcurement component, in version 9.1.\nThe flaw allows an unauthenticated remote attacker to gain unauthorized access to sensitive information and manipulate critical data within the application.\nThe vulnerability is characterized by high severity with a CVSS 3.1 base score of 9.1, as it permits unauthorized creation, deletion, and modification of accessible data, as well as full unauthorized data exposure.\nThe attack vector is network-based, utilizing the HTTP protocol, and does not require prior authentication or user interaction to succeed.\nGiven the low complexity of exploitation and the lack of required privileges, this vulnerability poses a significant risk to the confidentiality and integrity of the affected PeopleSoft environment.\nOrganizations using PeopleSoft Enterprise FIN Common Objects Argentina version 9.1 are highly susceptible to malicious actors seeking to exfiltrate or corrupt enterprise-level financial and procurement data.",
  "technicalDetails": "The vulnerability resides within the eProcurement component of the PeopleSoft Enterprise FIN Common Objects Argentina product suite in version 9.1.\nThe root cause of this vulnerability lies in the improper implementation of access control mechanisms or insufficient session validation within the HTTP-accessible interfaces of the eProcurement module.\nBecause the component fails to verify the identity of the requester, it processes requests from unauthenticated network entities as if they were authorized users.\nThe attack flow begins when an unauthenticated attacker transmits specially crafted HTTP requests targeting the vulnerable eProcurement endpoints.\nDue to the lack of restrictive authentication checks (AV:N/AC:L/PR:N/UI:N), the application processes these malicious inputs without validating the requestor's credentials or permissions.\nThe attacker is capable of executing unauthorized operations, including the creation of new records, modification of existing entries, and the deletion of sensitive financial documentation stored within the system.\nFurthermore, the vulnerability allows for the retrieval of sensitive information by bypassing the standard authorization layer that should otherwise govern access to the PeopleSoft database.\nThe impact on confidentiality is high, as an attacker can exfiltrate protected financial records, and the impact on integrity is equally high, as the attacker can perform unauthorized data manipulation.\nThe lack of integrity checks effectively permits the unauthorized injection or tampering of procurement-related data, which could lead to significant operational disruptions or financial fraud.\nThe vulnerability is limited to version 9.1 of the specified product, and because it resides in a core component, it potentially exposes all data reachable by the eProcurement application user identity, which often possesses elevated privileges within the PeopleSoft environment.\nPost-exploitation, the attacker maintains the ability to persist in their unauthorized data access until the underlying session or system configuration is addressed, potentially leading to long-term exposure of sensitive corporate information."
}
CVE-2026-61238: PeopleSoft eProcurement Unauthorized Data Access (CRITICAL Severity, CVSS: 9.1) - Sceawere