CVE-2026-61233: Infoleak
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle PeopleSoft Enterprise FIN Common Objects Brazil (Integration)to a version that resolves this vulnerability.Fixed in 9.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61233?
CVE-2026-61233 has a critical severity rating of 9.8.
How do I fix CVE-2026-61233?
To fix CVE-2026-61233, you should apply the latest security updates provided by Oracle for PeopleSoft Enterprise FIN Common Objects Brazil.
What type of vulnerability is CVE-2026-61233?
CVE-2026-61233 is classified as an information leak vulnerability.
Who is affected by CVE-2026-61233?
Organizations using Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1 are affected by CVE-2026-61233.
What are the attack vectors for CVE-2026-61233?
CVE-2026-61233 can be exploited by an unauthenticated attacker with network access via HTTP.