cve-2026-83147
HIGH CVSS 7.8 opencve
Description
Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Timeline
- Published
- 2026-09-15 20:18 UTC
- Last Modified
- 2026-09-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
mitre | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-83147",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "9.1"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "PeopleSoft Enterprise FIN Inventory Brazil",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "peoplesoft_enterprise_fin_inventory_brazil",
"vendor": "oracle"
}
],
"created": "2026-09-17T02:15:08.694278+00:00",
"updated": "2026-09-20T09:30:18.187737+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_fin_inventory_brazil"
]
},
"epss": {
"score": 0.00144
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_inventory_brazil:9.1:*:*:*:*:*:*:*"
],
"created": "2026-09-15T20:03:36.980000+00:00",
"description": "Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/83xxx/CVE-2026-83147.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-17T13:00:16.314000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_fin_inventory_brazil"
],
"weaknesses": []
},
"nvd": {
"cpes": [],
"created": "2026-09-15T20:18:25.410000+00:00",
"description": "Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-83147.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-17T14:17:34.393000+00:00",
"vendors": [],
"weaknesses": [
"CWE-269"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-15T20:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_fin_inventory_brazil"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_inventory_brazil:9.1:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_fin_inventory_brazil"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "8ee32285-337a-44ba-a543-2b7fa08bf2a9"
},
{
"created": "2026-09-17T02:30:00+00:00",
"data": [
{
"details": {
"new": "PeopleSoft FIN Inventory Brazil Vulnerability Allows Full Takeover by Low‑Privilege Users",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284",
"CWE-862"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "c2bbee8d-a9b7-437a-8327-6b3dde29af24"
},
{
"created": "2026-09-17T14:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-269"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "be4287ad-fcdf-4315-9b8e-ebf71296c511"
},
{
"created": "2026-09-18T21:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "PeopleSoft FIN Inventory Brazil Vulnerability Allows Full Takeover by Low‑Privilege Users"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-284",
"CWE-862"
]
},
"type": "weaknesses"
}
],
"id": "87c26244-d776-491a-8eff-75612e077f88"
},
{
"created": "2026-09-19T02:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "69aa57a8-5895-4f9b-9ee1-3bd1c411599b"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_inventory_brazil:9.1:*:*:*:*:*:*:*"
],
"providers": [
"mitre"
]
},
"created": {
"data": "2026-09-15T20:03:36.980000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00144
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2026-09-18T21:15:14.109434+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_fin_inventory_brazil"
],
"providers": [
"mitre",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-269"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-15T20:03:36.980000+00:00",
"description": "Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-09-17T12:51:08.677000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/83xxx/CVE-2026-83147.json",
"weaknesses": [
"CWE-269"
]
}
}