Vulnerability in Cash Management Product by Oracle PeopleSoft
CVE-2026-60597

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60597?

A security flaw exists in the Cash Management component of Oracle PeopleSoft Enterprise FIN, allowing an unauthenticated attacker with network access via HTTP to potentially compromise the system. Despite the focus on the Cash Management product, the exploitation could extend its effects to other interconnected products. Successfully exploiting this vulnerability could lead to unauthorized creation, deletion, or modification of critical data, risking the integrity and confidentiality of sensitive information accessible within the PeopleSoft Enterprise FIN Cash Management application.

Affected Version(s)

PeopleSoft Enterprise FIN Cash Management 9.2

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.