Summary
CVE-2026-61239 is a critical missing authentication vulnerability in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1, carrying a CVSS 3.1 base score of 9.9. The flaw allows unauthenticated remote attackers to access critical functions over HTTP with no user interaction required, enabling unauthorized creation, deletion, or modification of critical data, as well as partial read access to sensitive information and limited denial of service. The Changed scope indicates that successful exploitation can have impact beyond the directly vulnerable component.
Technical details
- Root cause: Missing authentication for a critical function (CWE-306) combined with improper access control (CWE-284) in the eProcurement component of the PeopleSoft FIN Common Objects Argentina module
- Trigger conditions: No authentication is required and no user interaction is needed; attack complexity is low, making exploitation straightforward for any network-reachable attacker
- Attack vector: Network-accessible via HTTP; an unauthenticated remote attacker can exploit the flaw directly against internet-exposed PeopleSoft instances
- Impact: Unauthorized creation, deletion, or modification of critical data (High Integrity); partial read access to sensitive information (Low Confidentiality); partial denial of service (Low Availability); scope is Changed, indicating the impact can extend to components beyond the initially compromised one
Affected software
- Oracle PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1
Severity
CVSS v3.1 base score: 9.9 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Mitigation and recommended actions
- Immediate: Apply the patches provided in the Oracle Critical Patch Update for July 2026 (cpujul2026)
- Organizations should confirm whether their PeopleSoft deployment includes the FIN Common Objects Argentina module at version 9.1 and treat patching as a priority given the unauthenticated, network-exploitable nature of the vulnerability
- Until patching is complete, consider restricting network-level access to PeopleSoft eProcurement endpoints from untrusted or external networks as a temporary mitigation
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

