Unauthenticated Data Access Vulnerability in Oracle PeopleSoft eProcurement
CVE-2026-61234
7.4HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-61234?
A vulnerability in Oracle's PeopleSoft Enterprise FIN Common Objects Brazil component, specifically in eProcurement, allows an unauthenticated attacker with network access via HTTP to compromise critical data. This flaw enables unauthorized creation, deletion, or modification of accessible data within the system. Attackers can gain unauthorized access, which may lead to significant breaches of confidentiality and integrity across all accessible data.
Affected Version(s)
PeopleSoft Enterprise FIN Common Objects Brazil 9.1