PatchSiren cyber security CVE debrief
CVE-2026-60597 Oracle Corporation CVE debrief
A high-severity vulnerability was discovered in Oracle PeopleSoft Enterprise FIN Cash Management, affecting version 9.2. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. The vulnerability, tracked as CVE-2026-60597, has a CVSS 3.1 Base Score of 8.7, indicating a high level of severity. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise FIN Cash Management accessible data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Cash Management accessible data. Organizations should prioritize patching this vulnerability to prevent potential unauthorized access and data manipulation. Further verification is needed to confirm the scope of affected systems and to validate vendor guidance.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Cash Management
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Organizations using Oracle PeopleSoft Enterprise FIN Cash Management version 9.2 should prioritize patching this vulnerability to prevent potential unauthorized access and data manipulation.
Technical summary
The vulnerability, CVE-2026-60597, is a high-severity issue in Oracle PeopleSoft Enterprise FIN Cash Management, with a CVSS 3.1 Base Score of 8.7. It allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise FIN Cash Management accessible data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Cash Management accessible data.
Defensive priority
High
Recommended defensive actions
- Apply the patch provided by Oracle as soon as possible
- Conduct a thorough inventory of PeopleSoft Enterprise FIN Cash Management instances to ensure all affected systems are identified and patched
- Implement compensating controls, such as network segmentation or access restrictions, to limit the attack surface
- Monitor system logs for suspicious activity
- Consider vulnerability scanning and penetration testing to validate system security
Evidence notes
The CVE record was published on 2026-07-21T22:17:59.840Z and was last modified on 2026-07-27T16:18:08.707Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability. Further verification is needed to confirm the scope of affected systems and to validate vendor guidance.
Official resources
-
CVE-2026-60597 CVE record
CVE.org
-
CVE-2026-60597 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:59.840Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.