A critical, easily exploitable vulnerability in Oracle PeopleSoft Enterprise FIN Expenses 9.2 lets unauthenticated attackers with network access fully compromise expense data over HTTP, carrying a CVSS 3.1 base score of 9.4.
What Is It
CVE-2026-61203 is a critical vulnerability in the Expenses component of Oracle PeopleSoft Enterprise FIN Expenses. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. No privileges, user interaction, or local access are required. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L, reflecting a network attack vector, low complexity, and no authentication.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to all PeopleSoft Enterprise FIN Expenses accessible data, as well as unauthorized read access to that same data. Attackers can also cause a partial denial of service (partial DOS) of the product. With high confidentiality and integrity impacts and a base score of 9.4, this represents near-complete compromise of the affected application's data by a remote, unauthenticated party. PeopleSoft financial systems handle sensitive expense and accounting records, raising the stakes for exposure.
What's Vulnerable
- Product: Oracle PeopleSoft Enterprise FIN Expenses
- Component: Expenses
- Affected version: 9.2 (the supported version identified as affected)
- Vendor: Oracle Corporation
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running PeopleSoft Enterprise FIN Expenses 9.2 should apply the fixes described in the Oracle Critical Patch Update Advisory as their required remediation. The NVD record currently lists a status of "Received," and no CISA KEV entry accompanies this CVE, so there is no confirmation of active exploitation at this time.