Unauthenticated Data Access Vulnerability in Oracle PeopleSoft eProcurement
CVE-2026-61234

7.4HIGH

What is CVE-2026-61234?

A vulnerability in Oracle's PeopleSoft Enterprise FIN Common Objects Brazil component, specifically in eProcurement, allows an unauthenticated attacker with network access via HTTP to compromise critical data. This flaw enables unauthorized creation, deletion, or modification of accessible data within the system. Attackers can gain unauthorized access, which may lead to significant breaches of confidentiality and integrity across all accessible data.

Affected Version(s)

PeopleSoft Enterprise FIN Common Objects Brazil 9.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.