CVE-2026-61237

Oracle · PeopleSoft Enterprise FIN Common Objects Argentina

An unauthenticated vulnerability in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina enables remote attackers to compromise the system over HTTP.

Executive summary

An unauthenticated remote attack vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects Argentina permits unauthorized data access and potential partial denial of service.

Vulnerability

This vulnerability resides in the Integration component and is easily exploitable by an unauthenticated attacker using network access via HTTP.

Business impact

The vulnerability allows for unauthorized access to, or modification of, critical business data stored within the PeopleSoft environment. With a CVSS score of 9.9, the potential for a complete system compromise and partial denial of service poses a catastrophic risk to organizational workflows and data confidentiality.

Remediation

Immediate Action: Apply the relevant security patches released in the July 2026 Oracle Critical Patch Update for the affected PeopleSoft component.

Proactive Monitoring: Monitor HTTP traffic logs for suspicious patterns or unexpected requests targeting the Integration component.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block malicious or malformed HTTP requests directed at PeopleSoft interfaces.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the ease of exploitability and the lack of authentication required, this issue is a high-priority risk. Administrators must verify their version status and apply the necessary vendor patches as soon as possible to ensure the integrity and availability of the PeopleSoft environment.