Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw (CWE‑284) in the Integration and Interfaces component of Oracle PeopleSoft Enterprise CS Campus Community. Based on the description, it is inferred that a low‑privileged attacker who can reach the system over HTTP can craft requests that bypass authentication controls and execute code. The impact is full compromise of confidentiality, integrity, and availability, enabling the attacker to read, modify, delete data and disrupt service operation.

Affected Systems

Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is the affected product. The vulnerable component is the Integration and Interfaces module, which exposes network‑reachable HTTP endpoints used in campus community deployments.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high‑severity vulnerability, with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The EPSS score of less than 1 % and the absence from CISA’s KEV database suggest that no publicly documented exploitation has been observed. Nevertheless, the low privilege requirement and open HTTP interface mean that any actor on the network can potentially exploit the flaw, making the attack path straightforward and the risk significant until a vendor patch is applied.

Generated by OpenCVE AI on August 2, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch released by Oracle for PeopleSoft Enterprise CS Campus Community 9.2.38 (see Oracle CPU July 2026).
  • Restrict HTTP access to the Integration and Interfaces endpoints using firewalls or network segmentation to minimise the attack surface until a patch is available.
  • Monitor web traffic for abnormal request patterns to the integration module and configure alerts for possible exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Control Exploit in Oracle PeopleSoft

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Code Execution in PeopleSoft Enterprise CS Campus Community Integration Module
Weaknesses CWE-704
CWE-94

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Code Execution in PeopleSoft Enterprise CS Campus Community Integration Module
Weaknesses CWE-704
CWE-94

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:10.225Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60594

cve-icon Vulnrichment

Updated: 2026-07-27T15:33:15.288Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses