Summary
CVE-2026-61245 is a critical authentication bypass vulnerability affecting Oracle PeopleSoft Enterprise FIN Manufacturing Brazil version 9.1, specifically the Integration component. Rooted in missing authentication controls on critical functionality (CWE-306) and improper access control (CWE-284), the flaw allows an unauthenticated remote attacker to gain complete control of the affected system over HTTPS without any user interaction. It was disclosed on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update and carries a CVSS v3.1 base score of 9.8 (CRITICAL).
Technical details
- Root cause: Missing authentication for a critical integration function (CWE-306) combined with improper access control enforcement (CWE-284), leaving sensitive backend functionality exposed to unauthenticated network requests.
- Trigger conditions: An attacker needs only network access to the target system via HTTPS; no credentials, no prior account, and no victim interaction are required.
- Attack vector: Remote, unauthenticated exploitation over HTTPS. Attack complexity is Low, with no privileges required and no user interaction needed.
- Impact: High across all three impact dimensions — Confidentiality, Integrity, and Availability — amounting to full takeover of the affected PeopleSoft application instance. Successful exploitation can expose sensitive financial and manufacturing data, allow unauthorized modification of records, and disrupt application availability.
Affected software
- Oracle PeopleSoft Enterprise FIN Manufacturing Brazil — version 9.1 (Integration component)
Severity
- CVSS v3.1 Base Score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s Critical Patch Update released on July 21, 2026. Oracle’s CPU is the official vendor-provided fix for this vulnerability. Organizations should consult the Oracle CPU July 2026 advisory for the specific patch applicable to their PeopleSoft deployment.
- If patching is not immediately possible: Restrict network access to the PeopleSoft Integration component — block unauthenticated external HTTPS access to integration endpoints via perimeter firewall or web application firewall rules until the patch can be applied. Additionally, review audit logs for anomalous unauthenticated requests to integration endpoints.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

