PatchSiren cyber security CVE debrief
CVE-2026-61203 Oracle Corporation CVE debrief
A critical vulnerability was discovered in PeopleSoft Enterprise FIN Expenses. This vulnerability, tracked as CVE-2026-61203, has a CVSS score of 9.4 and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data. Additionally, attackers may cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Expenses
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Organizations using PeopleSoft Enterprise FIN Expenses version 9.2 should prioritize patching this vulnerability to prevent potential exploitation. The vulnerability's high CVSS score and potential impact on data confidentiality, integrity, and availability make it a critical concern for affected organizations.
Technical summary
CVE-2026-61203 is a vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Expenses accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).
Defensive priority
High
Recommended defensive actions
- Apply the patch provided by Oracle as soon as possible
- Conduct a thorough review of PeopleSoft Enterprise FIN Expenses configurations and logs to detect any potential exploitation attempts
- Implement additional security measures such as network segmentation and access controls to limit the attack surface
- Monitor system activity closely for signs of exploitation
- Consider compensating controls such as web application firewalls to detect and prevent exploitation attempts
Evidence notes
The CVE record was published on 2026-07-21T22:18:52.063Z and was last modified on 2026-07-22T20:17:05.507Z. The NVD entry is currently being reviewed. Oracle has provided a patch for this vulnerability, which should be applied as soon as possible. Organizations should also conduct a thorough review of PeopleSoft Enterprise FIN Expenses configurations and logs to detect any potential exploitation attempts. Additional security measures, such as network segmentation and access controls, should be implemented to limit the attack surface. System activity should be closely monitored for signs of exploitation. Consider implementing compensating controls, such as web application firewalls, to detect and prevent exploitation attempts. Evidence is limited, and defenders should verify the affected scope and severity with the vendor.
Official resources
-
CVE-2026-61203 CVE record
CVE.org
-
CVE-2026-61203 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:52.063Z and has not been modified since then.