Summary
CVE-2026-71112 is a high-severity vulnerability in the Security component of Oracle PeopleSoft Enterprise FIN Common Objects, version 9.2. It allows an unauthenticated attacker with network access via HTTP to compromise and take over PeopleSoft Enterprise FIN Common Objects, impacting confidentiality, integrity, and availability. Oracle disclosed the issue in the August 2026 Critical Security Patch Update.
Technical details
- Root cause: a flaw in the Security component of PeopleSoft Enterprise FIN Common Objects.
- Attack vector: network, exploited over HTTP against the exposed PeopleSoft application.
- Authentication: no privileges or user interaction are required to exploit.
- Attack complexity: rated high, meaning exploitation requires specific conditions or additional effort ("difficult to exploit"), per Oracle’s description.
- Impact: successful exploitation results in complete compromise ("takeover") of PeopleSoft Enterprise FIN Common Objects, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle PeopleSoft Enterprise FIN Common Objects — version 9.2
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle August 2026 Critical Security Patch Update (CPU), which contains the fix for CVE-2026-71112, to all affected PeopleSoft Enterprise FIN Common Objects 9.2 deployments.
- If immediate patching is not possible: limit network exposure of PeopleSoft Enterprise application servers to trusted networks only, and monitor internet-facing PeopleSoft instances for anomalous HTTP requests targeting the Security/FIN Common Objects components until the patch can be applied.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Named response header (
set-cookie):PSJSESSIONID

