PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61203 Oracle Corporation CVE debrief

A critical vulnerability was discovered in PeopleSoft Enterprise FIN Expenses. This vulnerability, tracked as CVE-2026-61203, has a CVSS score of 9.4 and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data. Additionally, attackers may cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Expenses
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Organizations using PeopleSoft Enterprise FIN Expenses version 9.2 should prioritize patching this vulnerability to prevent potential exploitation. The vulnerability's high CVSS score and potential impact on data confidentiality, integrity, and availability make it a critical concern for affected organizations.

Technical summary

CVE-2026-61203 is a vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Expenses accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).

Defensive priority

High

Recommended defensive actions

  • Apply the patch provided by Oracle as soon as possible
  • Conduct a thorough review of PeopleSoft Enterprise FIN Expenses configurations and logs to detect any potential exploitation attempts
  • Implement additional security measures such as network segmentation and access controls to limit the attack surface
  • Monitor system activity closely for signs of exploitation
  • Consider compensating controls such as web application firewalls to detect and prevent exploitation attempts

Evidence notes

The CVE record was published on 2026-07-21T22:18:52.063Z and was last modified on 2026-07-22T20:17:05.507Z. The NVD entry is currently being reviewed. Oracle has provided a patch for this vulnerability, which should be applied as soon as possible. Organizations should also conduct a thorough review of PeopleSoft Enterprise FIN Expenses configurations and logs to detect any potential exploitation attempts. Additional security measures, such as network segmentation and access controls, should be implemented to limit the attack surface. System activity should be closely monitored for signs of exploitation. Consider implementing compensating controls, such as web application firewalls, to detect and prevent exploitation attempts. Evidence is limited, and defenders should verify the affected scope and severity with the vendor.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:52.063Z and has not been modified since then.