Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-06-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 contains an easily exploitable vulnerability within the Integration and Interfaces component. A high‑privileged attacker with HTTPS network access can gain the ability to create, delete or modify critical data, as well as read all data exposed by the application. The vulnerability leads to confidentiality and integrity loss but does not directly impact availability.

Affected Systems

The affected product is Oracle Corporation’s PeopleSoft Enterprise CS Campus Community, specifically version 9.2.38. No other versions or products are listed as affected.

Risk and Exploitability

The CVSS 3.1 score of 6.5 reflects moderate to high severity, and the low EPSS score (<1%) indicates that exploitation is currently unlikely but not impossible. The attack vector is inferred to be network based over HTTPS, requiring the attacker to possess high‑privilege credentials or exploit a privilege escalation flaw. Because the vulnerability is not listed in the CISA KEV catalog, no known widespread exploits have been reported, yet the impact if exploited is significant for organizations relying on the affected PeopleSoft deployment.

Generated by OpenCVE AI on June 17, 2026 at 18:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Oracle to obtain and apply the available patch for PeopleSoft Enterprise CS Campus Community 9.2.38
  • Restrict HTTPS access to the PeopleSoft interfaces to trusted network segments or VPNs to limit exposure to high‑privileged attackers
  • Implement application‑level access controls or firewall rules to block unauthorized data modification requests until the patch is applied

Generated by OpenCVE AI on June 17, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:36:16.440Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46979

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T02:45:02Z

Weaknesses

No weakness.