CVE-2026-61057
Analyzed Analyzed - Analysis Complete

Unauthenticated Data Access in PeopleSoft FIN eSettlements

Vulnerability report for CVE-2026-61057, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-04

Assigner: Oracle

Description

Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN eSettlements. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN eSettlements accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-04
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle peoplesoft_enterprise_fin_esettlements 9.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle PeopleSoft Enterprise FIN eSettlements version 9.2. It allows an unauthenticated attacker with network access via HTTP to potentially read or modify some data within the eSettlements component. The attack requires network access but no user interaction.

Detection Guidance

Detection requires monitoring for unauthorized access attempts to the PeopleSoft Enterprise FIN eSettlements component via HTTP. Check server logs for unusual HTTP requests targeting the eSettlements module. Ensure network traffic analysis tools are in place to identify suspicious patterns.

Impact Analysis

If exploited, this vulnerability could let an attacker access or alter sensitive financial settlement data without authorization. This may lead to financial loss, data corruption, or unauthorized transactions depending on the affected system's use.

Compliance Impact

This vulnerability allows unauthorized read and limited write access to sensitive financial data in PeopleSoft Enterprise FIN eSettlements. This could lead to violations of data protection regulations like GDPR or HIPAA if personal or health information is exposed or altered.

Mitigation Strategies

Apply the latest Oracle PeopleSoft patches immediately. Restrict network access to the eSettlements component via firewall rules. Monitor and audit database access for unauthorized changes. Consider disabling the eSettlements module if not in use until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61057. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart