Summary
CVE-2026-60597 is a high-severity vulnerability in Oracle PeopleSoft Enterprise FIN Cash Management version 9.2, addressed in Oracle’s July 2026 Critical Patch Update. An unauthenticated, network-accessible attacker who successfully exploits this flaw can gain unauthorized access to all accessible data and perform unauthorized creation, deletion, or modification of critical data — with impact explicitly extending beyond the directly vulnerable component to other products. The CVSS v3.1 base score is 8.7 (HIGH).
Technical details
- Root cause: The specific vulnerability class is not disclosed in the official CVE record; Oracle characterizes this as a difficult-to-exploit flaw in the Cash Management component of PeopleSoft Enterprise FIN, accessible over HTTP
- Trigger conditions: Attack complexity is rated High, meaning specific conditions or configurations must be present for exploitation; however, no privileges and no user interaction are required once those conditions are met
- Attack vector: Unauthenticated, network-based exploitation over HTTP — the attacker requires no account or session on the target system
- Impact: Full unauthorized read access to all accessible data (Confidentiality: High) and unauthorized creation, deletion, or modification of critical data (Integrity: High); Oracle’s Scope: Changed rating indicates successful exploitation can affect resources and data beyond the directly targeted Cash Management component; no availability impact is recorded
Affected software
- Oracle PeopleSoft Enterprise FIN Cash Management, version 9.2
Severity
CVSS v3.1 Base Score: 8.7 (HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the security patches provided in Oracle’s July 2026 Critical Patch Update, available through Oracle’s My Oracle Support portal
- If immediate patching is not feasible: Restrict internet-facing access to PeopleSoft FIN Cash Management web tiers and enforce network-level controls (firewall rules, IP allowlisting) to reduce the attack surface until patches can be applied
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

