SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61203 2026-07-21

CVE-2026-61203: Critical Unauthenticated Flaw in Oracle PeopleSoft FIN Expenses

"A critical, easily exploitable vulnerability in Oracle PeopleSoft Enterprise FIN Expenses 9.2 lets unauthenticated attackers with network access fully compromise expense data over HTTP, carrying a CVSS 3.1 base score of…"

A critical, easily exploitable vulnerability in Oracle PeopleSoft Enterprise FIN Expenses 9.2 lets unauthenticated attackers with network access fully compromise expense data over HTTP, carrying a CVSS 3.1 base score of 9.4.

What Is It

CVE-2026-61203 is a critical vulnerability in the Expenses component of Oracle PeopleSoft Enterprise FIN Expenses. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. No privileges, user interaction, or local access are required. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L, reflecting a network attack vector, low complexity, and no authentication.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to all PeopleSoft Enterprise FIN Expenses accessible data, as well as unauthorized read access to that same data. Attackers can also cause a partial denial of service (partial DOS) of the product. With high confidentiality and integrity impacts and a base score of 9.4, this represents near-complete compromise of the affected application's data by a remote, unauthenticated party. PeopleSoft financial systems handle sensitive expense and accounting records, raising the stakes for exposure.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running PeopleSoft Enterprise FIN Expenses 9.2 should apply the fixes described in the Oracle Critical Patch Update Advisory as their required remediation. The NVD record currently lists a status of "Received," and no CISA KEV entry accompanies this CVE, so there is no confirmation of active exploitation at this time.

Sources