Summary
CVE-2026-61087 is a high-severity improper access control vulnerability affecting Oracle PeopleSoft Enterprise FIN Payables version 9.2. The flaw allows an unauthenticated, remote attacker to gain unauthorized access to critical data — or complete access to all data — within the FIN Payables module, exploitable over HTTP with no privileges or user interaction required. Disclosed as part of Oracle’s July 2026 Critical Patch Update, it carries a CVSS v3.1 base score of 7.5 (HIGH).
Technical details
- Root cause: Improper access control (CWE-284) in the Security component of Oracle PeopleSoft Enterprise FIN Payables, enabling unauthenticated requests to reach protected data resources.
- Trigger conditions: No authentication, privileges, or user interaction are required. Oracle’s advisory describes this as an "easily exploitable" vulnerability, meaning no special configuration or environmental conditions are needed.
- Attack vector: Remotely exploitable over HTTP from the network. Any internet-facing PeopleSoft FIN Payables instance is directly reachable by an attacker without any prior foothold.
- Impact: Successful exploitation allows an attacker to obtain unauthorized access to critical data, or complete access to all data accessible within PeopleSoft Enterprise FIN Payables — which may include sensitive financial records, vendor payment data, and accounts payable information managed by the module.
Affected software
- Oracle PeopleSoft Enterprise FIN Payables, version 9.2
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU July 2026) for PeopleSoft. Oracle’s patch availability documentation (CPU277) provides specific installation instructions for PeopleSoft products. Oracle strongly recommends applying Critical Patch Update patches as soon as possible.
- If immediate patching is not feasible: Restrict network-level access to PeopleSoft FIN Payables HTTP endpoints to trusted IP ranges only, and prevent unauthenticated external access through firewall or web application gateway controls to reduce attack surface while patching is scheduled.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

