Sceawere
Vulnerability Detail
CVE-2026-61244Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Manufacturing Unauthenticated Data Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Manufacturing Argentina
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Manufacturing Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Manufacturing Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Manufacturing Argentina accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Manufacturing Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Manufacturing Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Manufacturing Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-07-21T22:18:55.230Z",
"pubdate": "2026-07-21T22:18:55.230Z",
"executiveSummary": "This vulnerability affects Oracle PeopleSoft Enterprise FIN Manufacturing Argentina version 9.1, specifically within the Manufacturing component.\nThe flaw allows an unauthenticated, remote attacker to gain unauthorized access to critical data and perform unauthorized modifications or deletions of data through HTTP requests.\nThe vulnerability is classified as highly exploitable, requiring no prior authentication or user interaction, which poses a severe risk to the confidentiality and integrity of the affected environment.\nWith a CVSS 3.1 base score of 9.1, the lack of authentication mechanisms protecting the Manufacturing component allows for full access to sensitive business data.\nOrganizations using this version face a high risk of data breaches, data manipulation, and unauthorized state changes within their manufacturing systems due to the ease of remote exploitation over network vectors.",
"technicalDetails": "The vulnerability resides in the Manufacturing component of Oracle PeopleSoft Enterprise FIN Manufacturing Argentina version 9.1. The root cause is a failure to properly implement authentication and authorization controls for network-accessible HTTP endpoints.\nThe attack vector is network-based (AV:N), with a low complexity requirement (AC:L) and no necessity for authentication (PR:N) or user interaction (UI:N).\nThe exploitation flow initiates with an attacker sending specifically crafted HTTP requests directly to the exposed Manufacturing component. Because the component lacks robust identity verification, the application treats these requests as legitimate, allowing the attacker to bypass access control lists (ACLs) and application-level security boundaries.\nOnce the attacker successfully interacts with the vulnerable Manufacturing component, they can execute unauthorized operations. This includes the ability to create new records, delete existing critical data, or modify stored information within the PeopleSoft database ecosystem.\nThe impact on confidentiality (C:H) is significant, as an attacker can exfiltrate sensitive business information stored within the component. The impact on integrity (I:H) is equally severe, as the lack of constraints allows for arbitrary modification of data, potentially leading to incorrect supply chain reporting, illicit process alterations, or unauthorized transaction processing.\nThe scope (S:U) of the vulnerability is limited to the PeopleSoft application, meaning the impact remains contained within the application's data layer, though the damage potential to that data is complete. The HTTP protocol usage allows attackers to interact with the service over common network channels, making discovery and exploitation straightforward for actors scanning for vulnerable PeopleSoft deployments.\nThe exploitation does not require advanced techniques like memory corruption or privilege escalation, as the vulnerability is inherent to the logic of the application's interface. By interacting with the HTTP-exposed API endpoints or web interfaces of the Manufacturing module, the attacker assumes the effective permissions of an application user without ever performing a login procedure."
}