Summary
CVE-2026-61073 is a high-severity improper access control vulnerability affecting the Purchasing component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil (version 9.1). Disclosed as part of Oracle’s July 2026 Critical Patch Update (July 21, 2026), the flaw allows unauthenticated remote attackers to gain unauthorized read access to sensitive financial data over HTTP, with no user interaction or special privileges required.
Technical details
- Root cause: Improper access control (CWE-284) in the Purchasing component of the PeopleSoft Enterprise FIN Common Objects Brazil module, allowing requests to bypass authorization checks entirely.
- Trigger conditions: An unauthenticated attacker with network access to the PeopleSoft web tier can send crafted HTTP requests directly to the affected Purchasing component endpoint.
- Attack vector: Network-accessible over HTTP; attack complexity is low, no authentication required, no user interaction required.
- Impact: High confidentiality impact — an attacker can gain unauthorized access to critical financial data managed within the Purchasing component. There is no impact to integrity or availability.
Affected software
- Oracle PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1
Severity
CVSS v3.1 Base Score: 7.5 (HIGH)
Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU), which contains the official fix for this vulnerability in PeopleSoft Enterprise FIN Common Objects Brazil 9.1.
- If patching is delayed: Restrict external and internal network access to PeopleSoft Purchasing component endpoints using firewall rules or network segmentation; limit HTTP access to trusted IP ranges only.
- Review PeopleSoft access logs for unauthorized or anomalous unauthenticated requests targeting Purchasing-related endpoints.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

