PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60597 Oracle Corporation CVE debrief

A high-severity vulnerability was discovered in Oracle PeopleSoft Enterprise FIN Cash Management, affecting version 9.2. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. The vulnerability, tracked as CVE-2026-60597, has a CVSS 3.1 Base Score of 8.7, indicating a high level of severity. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise FIN Cash Management accessible data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Cash Management accessible data. Organizations should prioritize patching this vulnerability to prevent potential unauthorized access and data manipulation. Further verification is needed to confirm the scope of affected systems and to validate vendor guidance.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Cash Management
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using Oracle PeopleSoft Enterprise FIN Cash Management version 9.2 should prioritize patching this vulnerability to prevent potential unauthorized access and data manipulation.

Technical summary

The vulnerability, CVE-2026-60597, is a high-severity issue in Oracle PeopleSoft Enterprise FIN Cash Management, with a CVSS 3.1 Base Score of 8.7. It allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise FIN Cash Management accessible data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Cash Management accessible data.

Defensive priority

High

Recommended defensive actions

  • Apply the patch provided by Oracle as soon as possible
  • Conduct a thorough inventory of PeopleSoft Enterprise FIN Cash Management instances to ensure all affected systems are identified and patched
  • Implement compensating controls, such as network segmentation or access restrictions, to limit the attack surface
  • Monitor system logs for suspicious activity
  • Consider vulnerability scanning and penetration testing to validate system security

Evidence notes

The CVE record was published on 2026-07-21T22:17:59.840Z and was last modified on 2026-07-27T16:18:08.707Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability. Further verification is needed to confirm the scope of affected systems and to validate vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:59.840Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.