{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Oracle heeft meerdere kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise PeopleTools, inclusief de modules Integration Broker, Data Mover, Configuration Manager, FIN Common Objects, FIN Lease Administration en CC Common Application Objects, specifiek in versies 8.61 tot en met 8.63 en 9.1 tot en met 9.2.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "De kwetsbaarheden in Oracle PeopleSoft Enterprise PeopleTools en gerelateerde modules stellen een aanvaller in staat om via netwerktoegang, vaak via HTTP of Oracle Net, zonder authenticatie of met lage privileges, het systeem volledig over te nemen of kritieke data te creëren, wijzigen of verwijderen. Sommige kwetsbaarheden vereisen gebruikersinteractie, andere niet. De impact betreft de vertrouwelijkheid, integriteit en beschikbaarheid van het systeem en de data. De kwetsbaarheden omvatten onder meer het omzeilen van authenticatie, privilege-escalatie, en het uitvoeren van ongeautoriseerde acties. Specifieke componenten zoals de Integration Broker en Configuration Manager zijn ook getroffen. De CVSS 3.1 basis scores variëren van 4.4 tot 9.8, waarbij meerdere kwetsbaarheden een hoge score hebben die duidt op een significante impact op de beveiliging van de systemen.",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Oracle heeft updates uitgebracht om de kwetsbaarheden in Oracle PeopleSoft Enterprise PeopleTools en de gerelateerde modules te verhelpen. Zie bijgevoegde referenties voor meer informatie.",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Exposure of Sensitive Information to an Unauthorized Actor",
                "title": "CWE-200"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "references": [
            {
                "category": "external",
                "summary": "Reference",
                "url": "https://www.oracle.com/security-alerts/cspuaug2026.html"
            }
        ],
        "title": "Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise",
        "tracking": {
            "current_release_date": "2026-08-19T11:13:31.828637Z",
            "generator": {
                "date": "2025-08-04T16:30:00Z",
                "engine": {
                    "name": "V.A.",
                    "version": "1.3"
                }
            },
            "id": "NCSC-2026-0316",
            "initial_release_date": "2026-08-19T11:13:31.828637Z",
            "revision_history": [
                {
                    "date": "2026-08-19T11:13:31.828637Z",
                    "number": "1.0.0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-1"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PeopleSoft"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-2"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PeopleSoft Enterprise CC Common Application Objects"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-3"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PeopleSoft Enterprise PeopleTools"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-4"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PeopleSoft Enterprise FIN Common Objects"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PeopleSoft Enterprise FIN Common Objects Brazil"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-6"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PeopleSoft Enterprise FIN Lease Administration"
                    }
                ],
                "category": "vendor",
                "name": "Oracle Corporation"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-60742",
            "notes": [
                {
                    "category": "description",
                    "text": "A high-severity vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63 allows unauthenticated remote attackers to potentially compromise system confidentiality, integrity, and availability via HTTP access.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60742 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60742.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60742"
        },
        {
            "cve": "CVE-2026-60821",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63 allows unauthenticated remote attackers to fully compromise the system via HTTP, with a CVSS 3.1 base score of 9.8 indicating severe impacts on confidentiality, integrity, and availability.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60821 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60821.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60821"
        },
        {
            "cve": "CVE-2026-60831",
            "notes": [
                {
                    "category": "description",
                    "text": "A high-severity vulnerability in Oracle PeopleSoft Enterprise PeopleTools Integration Broker (versions 8.61-8.63) enables unauthenticated remote attackers to compromise system confidentiality, integrity, and availability via HTTP.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60831 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60831.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60831"
        },
        {
            "cve": "CVE-2026-60856",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63 allows unauthenticated HTTP attackers to create, delete, or modify critical data, leading to unauthorized access with a CVSS 3.1 score of 7.4.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60856 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60856.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60856"
        },
        {
            "cve": "CVE-2026-60873",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise PeopleTools Data Mover (versions 8.61-8.63) allows a high-privileged attacker with infrastructure access and user interaction to manipulate critical data and cause partial denial of service, rated CVSS 7.2.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60873 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60873.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60873"
        },
        {
            "cve": "CVE-2026-60879",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools Configuration Manager (versions 8.61-8.63) allows low-privileged attackers with network SQL access to fully compromise the system, rated CVSS 3.1 8.8 for high impact.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60879 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60879.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60879"
        },
        {
            "cve": "CVE-2026-60883",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63 allows a high-privileged attacker with HTTP network access to fully compromise the system, with a CVSS 3.1 base score of 7.2.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60883 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60883.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60883"
        },
        {
            "cve": "CVE-2026-60884",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63 allows a low-privileged attacker with network access and user interaction to gain unauthorized read and write access to certain data, with a CVSS 3.1 base score of 4.4.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60884 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60884.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60884"
        },
        {
            "cve": "CVE-2026-60902",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63 allows low-privileged attackers with logon access to potentially take over the system, with a CVSS 3.1 base score of 7.0 indicating high impact.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60902 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60902.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60902"
        },
        {
            "cve": "CVE-2026-60967",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63 allows unauthenticated remote attackers to potentially take control of the system via HTTP, impacting confidentiality, integrity, and availability with a CVSS score of 8.8.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60967 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60967.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60967"
        },
        {
            "cve": "CVE-2026-60975",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 allows low-privileged authenticated users to create, delete, or modify critical data, impacting confidentiality and integrity with a CVSS 3.1 base score of 7.5.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-60975 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-60975.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-60975"
        },
        {
            "cve": "CVE-2026-61307",
            "notes": [
                {
                    "category": "description",
                    "text": "A high-severity vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects 9.2 allows unauthenticated network attackers via Oracle Net to potentially take control of the application, with a CVSS 3.1 score of 8.1.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-61307 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-61307.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-61307"
        },
        {
            "cve": "CVE-2026-70861",
            "notes": [
                {
                    "category": "description",
                    "text": "A high-privileged attacker can exploit a vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1 via T3 or IIOP to fully compromise the system, with a CVSS 3.1 base score of 7.2 indicating high impact.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-70861 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-70861.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-70861"
        },
        {
            "cve": "CVE-2026-71092",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle PeopleSoft Enterprise FIN Lease Administration 9.2 allows a low-privileged attacker with infrastructure access to create, delete, or modify critical data, with a CVSS 3.1 base score of 7.5.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-71092 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-71092.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-71092"
        },
        {
            "cve": "CVE-2026-71112",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects 9.2 allows unauthenticated remote attackers to potentially compromise system confidentiality, integrity, and availability via HTTP, with a CVSS 3.1 score of 8.1.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3",
                    "CSAFPID-4",
                    "CSAFPID-5",
                    "CSAFPID-6"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-71112 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-71112.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3",
                        "CSAFPID-4",
                        "CSAFPID-5",
                        "CSAFPID-6"
                    ]
                }
            ],
            "title": "CVE-2026-71112"
        }
    ]
}