Summary
CVE-2026-61232 is a high-severity improper access control vulnerability (CWE-284) affecting Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1. An unauthenticated remote attacker can exploit this flaw over HTTP to gain unauthorized access to sensitive data without any user interaction. It was disclosed on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update.
Technical details
- Root cause: Improper access control (CWE-284) in the Common Objects component of PeopleSoft Enterprise FIN Common Objects Brazil.
- Trigger conditions: The vulnerability is easily exploitable — an attacker requires only network access via HTTP; no authentication, no privileges, and no user interaction are needed.
- Attack vector: Network-accessible (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact — successful exploitation allows an unauthenticated attacker to gain unauthorized access to critical data accessible through the affected component. There is no integrity or availability impact.
Affected software
- Oracle PeopleSoft Enterprise FIN Common Objects Brazil — version 9.1
Severity
CVSS v3.1 Base Score: 7.5 (HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update, released July 21, 2026, which addresses this vulnerability. Refer to the Oracle CPU advisory for installation instructions and patch availability.
- If patching is not immediately possible: Restrict network access to PeopleSoft application servers at the perimeter, ensuring that internet-facing exposure of the PeopleSoft web interface is limited to authorized users via firewall rules or network segmentation.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

