CVE-2026-61237
A critical flaw in Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1 lets anyone on the network send HTTP requests to gain unauthorized access to sensitive data and modify or delete it. The vulnerability can also cause a partial denial of service.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle PeopleSoft Enterprise FIN Common Objects Argentina version 9.1 (Argentina product of Oracle PeopleSoft).
Real-world impact
An attacker could read confidential financial information, alter or delete records, and disrupt service for users of the affected PeopleSoft application.
Why this severity
The CVSS score of 9.9 reflects the high confidentiality impact (C:H) combined with a scope change (S:C) that allows the attacker to affect other components. The low integrity and availability scores are offset by the scope change, resulting in a critical overall score.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 31, 2026 · 22h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cpujul2026.…vendor advisory