Summary
CVE-2026-61074 is a high-severity missing authentication vulnerability affecting the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1. Published as part of Oracle’s July 2026 Critical Patch Update (July 21, 2026), this flaw allows an unauthenticated, remote attacker to exploit the system over HTTP, with potential for complete compromise of confidentiality, integrity, and availability. It carries a CVSS v3.1 base score of 8.1 (HIGH).
Technical details
- Root cause: Missing or improper authentication controls for critical functions within the eProcurement component (CWE-306: Missing Authentication for Critical Function; CWE-287: Improper Authentication; CWE-284: Improper Access Control).
- Trigger conditions: An unauthenticated attacker with network access via HTTP can send crafted requests targeting the vulnerable eProcurement endpoint. Oracle classifies the attack complexity as High, meaning specific environmental conditions must be met for successful exploitation.
- Attack vector: Network-accessible via HTTP; requires no credentials and no user interaction.
- Impact: Successful exploitation results in complete compromise of confidentiality, integrity, and availability of the affected PeopleSoft instance — consistent with unauthorized access to sensitive financial data, unauthorized modification of records, and potential disruption of system availability.
Affected software
- Oracle PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the security patches delivered in Oracle’s July 2026 Critical Patch Update, released July 21, 2026. Consult the Oracle CPU advisory for the specific patch set applicable to Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1.
- If immediate patching is not feasible: Restrict network-level access to PeopleSoft web portals and eProcurement endpoints from untrusted or external networks using firewall rules or network segmentation. This does not eliminate the vulnerability but significantly reduces the attack surface.
- Oracle strongly advises all customers to apply CPU patches without delay, as previously disclosed PeopleSoft vulnerabilities have been observed being exploited after public disclosure.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

