Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4620 articles · 179881 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-61233PATCHED
oracle · peoplesoft enterprise fin common objects brazil

CVE-2026-61233: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integratio

Description

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products

VendorProductVersions
oraclepeoplesoft enterprise fin common objects brazil9.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
oraclepeoplesoftcert_advisory90%

References

  • https://www.oracle.com/security-alerts/cpujul2026.html(vendor-advisory)

Related News (3 articles)

Tier B
CERT-FR18h ago
Multiples vulnérabilités dans Oracle PeopleSoft (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories1d ago
[NEU] [hoch] Oracle PeopleSoft: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-61233 | Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1 Integration Remote Code Execution
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.oracle.com/security-alerts/cpujul2026.html
PublishedJul 21, 2026
Last enriched1d agov2
Trending Score56
Source articles3
Independent3
Info Completeness6/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-35273EXPKEV
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
Trending: 146
CRITICALCVE-2026-46817EXPKEV
CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Trending: 58
CRITICALCVE-2026-60205
CVE-2026-60205: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Trending: 56
CRITICALCVE-2026-60198
CVE-2026-60198: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Trending: 56
CRITICALCVE-2026-60208
CVE-2026-60208: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Trending: 56

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: cweIds, mitreAttack
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Added CWE-94 (Improper Control of Generation of Code) and MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) based on confirmed Remote Code Execution attack vector.

cweIdsmitreAttack
via VulDB
v11d ago

Initial creation