CVE-2026-61239
This critical vulnerability in Oracle PeopleSoft’s eProcurement component (PeopleSoft Enterprise FIN Common Objects Argentina) allows an unauthenticated attacker to modify or delete data and cause a partial denial of service. The flaw can be exploited over HTTP without authentication and affects version 9.1.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1, used by organizations running PeopleSoft eProcurement.
Real-world impact
An attacker could create, delete, or change critical data, read sensitive information, and disrupt services for users of the affected PeopleSoft application.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is network‑based, requires no authentication, and can lead to high integrity impact, moderate confidentiality impact, and partial availability loss.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 31, 2026 · 22h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cpujul2026.…vendor advisory