CVE-2026-34306
Unauthorized Access via Network in Oracle PeopleSoft Projects
Publication date: 2026-04-21
Last updated on: 2026-04-24
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | peoplesoft_enterprise_fin_project_costing | 9.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows unauthorized access to critical data within PeopleSoft Enterprise FIN Project Costing, which could lead to exposure of sensitive information.
Such unauthorized access and potential data compromise may impact compliance with data protection regulations and standards like GDPR and HIPAA, which require safeguarding of sensitive and personal data.
However, the provided information does not specify exact compliance implications or regulatory impacts.
Can you explain this vulnerability to me?
This vulnerability exists in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft, specifically in the Projects component. It affects version 9.2 and allows a low privileged attacker with network access via HTTP to exploit the system easily.
Successful exploitation can lead to unauthorized access to critical data or even complete access to all data accessible through PeopleSoft Enterprise FIN Project Costing.
How can this vulnerability impact me? :
The impact of this vulnerability includes unauthorized access to sensitive and critical data within the PeopleSoft Enterprise FIN Project Costing system.
An attacker exploiting this vulnerability could gain complete access to all data accessible through the affected PeopleSoft component, potentially leading to data breaches or misuse of confidential information.