Sceawere

Vulnerability Detail

CVE-2026-71092UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft FIN Lease Administration Compromise

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Lease Administration
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease Administration executes to compromise PeopleSoft Enterprise FIN Lease Administration. While the vulnerability is in PeopleSoft Enterprise FIN Lease Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Lease Administration accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Lease Administration accessible data.
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease Administration executes to compromise PeopleSoft Enterprise FIN Lease Administration. While the vulnerability is in PeopleSoft Enterprise FIN Lease Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Lease Administration accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Lease Administration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:18:09.450Z",
  "pubdate": "2026-08-18T21:18:09.450Z",
  "executiveSummary": "A security vulnerability has been identified within the Lease Administration component of Oracle PeopleSoft Enterprise FIN version 9.2. This vulnerability presents significant risks to enterprise data security, allowing a low-privileged authenticated attacker with local infrastructure access to compromise the targeted application.\nAlthough the flaw originates specifically within the Lease Administration module, successful exploitation introduces a security scope change that can severely impact additional integrated Oracle products residing within the same architectural ecosystem.\nThe primary risk implications involve the complete compromise of data confidentiality and integrity. Successful exploitation grants unauthorized actors the capability to execute critical data modifications, deletions, and unauthorized data creation, alongside unhindered access to all accessible Lease Administration data repositories.\nThe vulnerability is characterized by a CVSS 3.1 Base Score of 7.5 with the vector string (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). Exploitation requires low privileges and local access to the underlying execution infrastructure, coupled with high attack complexity conditions, while requiring no user interaction.",
  "technicalDetails": "The vulnerability resides within the Lease Administration component of Oracle PeopleSoft Enterprise FIN version 9.2. The root cause stems from insufficient access controls, insecure handling of internal application logic, or improper privilege boundary enforcement within the component's execution context.\nAttack execution requires the adversary to possess pre-existing low-privileged access and interactive or programmatic logon capabilities directly to the underlying host infrastructure where the PeopleSoft Enterprise FIN Lease Administration instance executes. Network exposure for the initial vector is local (AV:L), meaning remote direct exploitation over network sockets is not the primary vector; however, the attack complexity is rated as high (AC:H), indicating that specific race conditions, environmental configurations, or precise timing mechanics are mandatory for successful exploitation.\nThe step-by-step attack flow proceeds as follows: First, the low-privileged attacker authenticates locally to the infrastructure hosting the target PeopleSoft environment using valid credentials. Second, leveraging the high attack complexity vector, the adversary interacts with local execution mechanisms, misconfigured file permissions, or inter-process communication channels associated with the Lease Administration component. Third, due to flawed authorization checks and the presence of a security scope change (S:C), the attacker bypasses standard application-layer segmentation.\nPost-exploitation impact is severe, resulting in unauthorized data manipulation. The attacker gains the ability to perform unauthorized creation, deletion, and modification of critical application data, alongside unrestricted read access to sensitive records across the primary product and significantly impacted secondary products. The CVSS vector confirms that availability impact remains null (A:N), but confidentiality (C:H) and integrity (I:H) impacts are absolute for the accessible data scope."
}
CVE-2026-71092: PeopleSoft FIN Lease Administration Compromise (HIGH Severity, CVSS: 7.5) - Sceawere