Sceawere
Vulnerability Detail
CVE-2026-61239Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft eProcurement Unauthenticated Remote Compromise
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Common Objects Argentina
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:54.793Z",
"pubdate": "2026-07-21T22:18:54.793Z",
"executiveSummary": "This vulnerability affects the PeopleSoft Enterprise FIN Common Objects Argentina product, specifically within the eProcurement component, version 9.1.\nThe vulnerability is a critical security flaw that allows an unauthenticated, remote attacker to gain unauthorized access to the system via HTTP.\nThe exploitation of this flaw allows for unauthorized read access to system data, as well as the ability to modify, create, or delete critical data.\nThe vulnerability involves a significant scope change, indicating that a compromise of the eProcurement component can lead to an impact on additional, interconnected Oracle PeopleSoft products.\nWith a CVSS 3.1 Base Score of 9.9, this vulnerability presents an extreme risk to organizational security, as it does not require user interaction or pre-existing privileges.\nAttackers can leverage this vulnerability to cause a partial denial of service (DoS) and gain persistent control over the data within the application.",
"technicalDetails": "The vulnerability exists within the PeopleSoft Enterprise FIN Common Objects Argentina component, specifically residing in the eProcurement module for version 9.1.\nThe root cause involves improper validation and sanitization of input processed by the eProcurement component, which is reachable via the HTTP protocol.\nBecause the attack vector is network-based (AV:N) and requires no authentication (PR:N) or user interaction (UI:N), the entry barrier for exploitation is exceptionally low.\nThe technical flow begins with the attacker sending a specially crafted HTTP request to the target PeopleSoft endpoint. Because the application fails to enforce appropriate security constraints at the eProcurement component level, the malicious request bypasses intended authorization logic.\nUpon successful execution, the attacker leverages the scope change (S:C) to traverse outside the primary container of the eProcurement component, affecting the broader PeopleSoft ecosystem. This privilege escalation path allows the attacker to execute arbitrary operations with the context of the application service account.\nThe payload behavior involves interacting with back-end database operations or application services to manipulate business-critical records. This includes, but is not limited to, the unauthorized insertion or modification of procurement orders, vendor details, or sensitive financial objects managed by the FIN Common Objects Argentina package.\nThe impact on confidentiality includes the unauthorized extraction of sensitive information accessible to the service account. The integrity impact allows for the unauthorized creation, deletion, or modification of data, potentially leading to significant financial or operational disruption.\nFurthermore, the vulnerability permits the execution of operations that result in a partial denial of service (A:L), potentially exhausting system resources or corrupting critical state information, thereby degrading system availability for legitimate users.\nThe combination of the high base score and the ability to affect multiple product domains highlights a flaw in the application's cross-component security architecture, where internal interfaces are exposed to unauthenticated network traffic."
}