CVE-2026-83420
nicheLocal Privilege Escalation in Oracle PeopleSoft FIN Engineering Brazil 9.1
CVE-2026-83420 is an easily exploitable flaw in the Engineering component of Oracle PeopleSoft Enterprise FIN Engineering Brazil, affecting supported version 9.1. It is triggered by a low-privileged attacker who already has logon access to the host or infrastructure where the product executes — no user interaction or special conditions are required. A successful attack lets the attacker fully compromise the PeopleSoft Enterprise FIN Engineering Brazil installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local attack vector). Organizations running the Brazil-specific financial engineering module on 9.1 are the only affected population. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83420 to your PeopleSoft Enterprise FIN Engineering Brazil 9.1 environment as soon as it is available. In the interim, restrict interactive and service-account logon access to the servers hosting this module to only trusted administrators, and enforce least-privilege OS permissions. Review local authentication logs on PeopleSoft hosts for suspicious low-privileged account activity.
| Oracle PeopleSoft Enterprise FIN Engineering Brazil (component: Engineering) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil executes to compromise PeopleSoft Enterprise FIN Engineering Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Engineering Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.