Description
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-04-21
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Data Access
Action: Apply Patch
AI Analysis

Impact

The issue lies in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records 9.2, permitting a low‑privileged, network‑based attacker to compromise the system over HTTP. The flaw represents an improper access control weakness, as it allows an attacker to bypass authorization controls. Although the exploit requires human interaction from a user other than the attacker, the specific steps are not fully described. If successful, an attacker can read or potentially manipulate all data available in the PeopleSoft system, resulting in significant confidentiality loss.

Affected Systems

Oracle Corporation's PeopleSoft Enterprise CS Student Records product, version 9.2, is affected. The vulnerability is limited to the Research Tracking component within that version.

Risk and Exploitability

The CVSS v3.1 base score of 5.7 indicates moderate risk, with a high impact on confidentiality. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting it is not a widely exploited vulnerability at present. The attacker must have low‑level network access and may need a target user to perform an action; the exact human interaction requirement is not specified, implying that the vulnerability could be targeted in environments where administrators or privileged users are inadvertently prompted. The attack vector is likely over the network via HTTP, and the exploit path relies on weaknesses in access control. Until mitigation is applied, the risk remains moderate but could worsen if additional attacker knowledge arises.

Generated by OpenCVE AI on April 22, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle PeopleSoft Enterprise CS Student Records 9.2 patch that addresses the Research Tracking access control issue.
  • Restrict HTTP access to the PeopleSoft application to trusted networks or enforce IP‑based restrictions.
  • Implement strict role‑based access control and ensure low‑privilege accounts cannot access critical data.
  • Enable logging and monitoring for unusual access patterns to detect potential exploitation.

Generated by OpenCVE AI on April 22, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in PeopleSoft Research Tracking
Weaknesses CWE-284
CWE-285

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Student Records
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_student_records:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Student Records
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Student Records
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-04-21T20:35:49.320Z

Reserved: 2026-04-01T20:03:40.833Z

Link: CVE-2026-35241

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-21T21:16:39.983

Modified: 2026-04-21T21:16:39.983

Link: CVE-2026-35241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T05:00:09Z

Weaknesses