CVE-2026-61062

Oracle · PeopleSoft Enterprise FIN Cash Management

A vulnerability in PeopleSoft Enterprise FIN Cash Management allows a local, low privileged attacker to compromise the application and potentially impact other products due to scope change.

Executive summary

A critical vulnerability in PeopleSoft Enterprise FIN Cash Management allows a local attacker to achieve system takeover and impact broader infrastructure.

Vulnerability

This vulnerability allows a low privileged attacker with logon access to the underlying infrastructure to compromise the application. The flaw involves a scope change, meaning exploitation can significantly impact additional products beyond the primary target.

Business impact

The risk of a scope change combined with full system takeover capabilities poses a severe threat to the entire PeopleSoft environment. With a CVSS score of 8.8, the ability for an attacker to escalate access from a low privileged account to a system-wide compromise necessitates immediate patching to prevent lateral movement and data breach.

Remediation

Immediate Action: Apply the security patches provided in the July 2026 Oracle Critical Patch Update.

Proactive Monitoring: Monitor infrastructure access logs for unauthorized local logins or privilege escalation attempts within the environment where PeopleSoft is hosted.

Compensating Controls: Restrict local shell access to the host server and enforce strict principle of least privilege for all user accounts to minimize the potential impact of a local compromise.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for cross-product impact, this vulnerability must be addressed as a critical priority. Administrators should apply the relevant Oracle updates immediately and verify that local access controls are strictly enforced to mitigate the risk of exploitation.