External risk intelligence

Oracle PeopleSoft eProcurement Critical Data Tampering and Denial of Service Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-61239

The vulnerability affects a PeopleSoft eProcurement component, which is a web-based enterprise application. Such applications are commonly deployed as internet-facing web portals or business services, making them reachable via HTTP from external networks.

Denial of Service

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle PeopleSoft's eProcurement component. This issue, easily exploitable over the network, could allow an attacker to gain unauthorized access to modify or delete critical data, read sensitive information, or disrupt service. The potential impact extends beyond the directly affected component, requiring an assessment of its relevance to our operations.

  • Unauthenticated network access can compromise critical data.
  • High impact vulnerability could affect core business operations.
  • Confirm relevance and exposure of PeopleSoft eProcurement.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted network requests over HTTP to the PeopleSoft Enterprise FIN Common Objects Argentina product. This can lead to unauthorized data access and modifications, potentially impacting additional products beyond the directly affected component.

  • Attacker needs network access.
  • Triggered via network requests.
  • Critical data access and modification.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise PeopleSoft Enterprise FIN Common Objects Argentina, potentially leading to unauthorized modifications or deletions of critical data, unauthorized reading of data, and a partial denial of service. While the vulnerability is within a specific component, its impact could extend to other interconnected PeopleSoft products.

  • Critical system data or accessible data.
  • Network access via HTTP.
  • Unauthorized data changes and partial denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle PeopleSoft's eProcurement component likely impacts teams responsible for enterprise resource planning (ERP) systems, including application owners, infrastructure support, and potentially vendor management. The first practical step is to confirm the presence and network accessibility of the affected PeopleSoft 9.1 instances, identify the business-criticality and accountable owner, and then prioritize remediation based on the assessed risk.

  • Application and ERP infrastructure teams own.
  • Verify PeopleSoft instance network exposure.
  • Plan and coordinate vendor-assisted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PeopleSoft Enterprise FIN Common Objects Argentina?

It is a specialized financial module within the Oracle PeopleSoft suite, specifically designed to support regulatory and business accounting requirements in Argentina. The affected eProcurement component is an enterprise tool used to manage purchasing workflows and supply chain interactions, typically integrated into broader ERP environments to track organizational spending and vendor engagements.

How does CVE-2026-61239 allow unauthorized access?

This vulnerability indicates a flaw in how the software validates incoming requests. Because the system fails to properly verify the identity of the user, an attacker can bypass traditional authentication gates. Once the security check is circumvented, the system treats the malicious commands as legitimate, granting the attacker the ability to read, change, or delete sensitive business information managed by the platform.

Do I need to be logged into PeopleSoft to trigger this?

No, you do not need to be an authorized user. The vulnerability is triggered by sending specially crafted HTTP requests to the target system over the network. It does not require prior knowledge of legitimate user credentials, nor does it rely on actions performed by someone already logged into the application. If the system is reachable, it is theoretically open to these requests.

Is my organization at risk if our PeopleSoft instance is internal?

Halo Surface Signal notes that eProcurement components are often deployed as web portals, which may be accessible via the internet. If your instance is reachable from an external network, the risk is higher. Even for internal-only instances, an attacker who has already breached your perimeter network could use this path to target the application, so internal placement is not a complete guarantee of safety.

What should I do first to address this vulnerability?

Begin by identifying which servers in your environment are running PeopleSoft version 9.1. Once identified, confirm whether those specific instances are accessible over your network. Determine who owns the application and coordinate with your ERP infrastructure team to review the vendor's latest security guidance, as applying the official software update provided by Oracle is the primary way to resolve this risk.

References