Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Contracts accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
References
| Link | Resource |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2026.html | Vendor Advisory |
Configurations
History
27 Apr 2026, 13:08
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.oracle.com/security-alerts/cpuapr2026.html - Vendor Advisory | |
| CPE | cpe:2.3:a:oracle:peoplesoft_enterprise_fin_contracts:9.2:*:*:*:*:*:*:* | |
| First Time |
Oracle peoplesoft Enterprise Fin Contracts
Oracle |
22 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-200 |
21 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 21:16
Updated : 2026-06-17 10:38
NVD link : CVE-2026-34300
Mitre link : CVE-2026-34300
CVE.ORG link : CVE-2026-34300
JSON object : View
Products Affected
oracle
- peoplesoft_enterprise_fin_contracts
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
