Description
Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Billing component of Oracle PeopleSoft Enterprise CS Student Financials and can be exploited by a low‑privileged attacker who has network connectivity to the HTTP interface. Successful exploitation results in a full compromise of the application, providing the attacker with complete control and exposing all sensitive information. The CVSS 3.1 score of 8.8 reflects severe impacts to confidentiality, integrity, and availability.

Affected Systems

The affected product is Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38, specifically the Billing component, as identified by the supplied CPE string. No other versions or products are listed as impacted.

Risk and Exploitability

Although the EPSS score is less than 1%, indicating a low probability of observed exploitation, the vulnerability is highly exploitable via HTTP without authentication and can be leveraged by anyone with network access. It is not currently listed in CISA’s KEV catalog, but its high CVSS score and the nature of the attack vector warrant urgent attention.

Generated by OpenCVE AI on August 2, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for PeopleSoft Enterprise CS Student Financials 9.2.38 (See Oracle security alert for details).
  • Restrict HTTP access to the PeopleSoft application by allowing only trusted IP ranges and blocking unauthenticated requests.
  • Monitor application and web server logs for anomalous HTTP traffic and unauthorized access attempts, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 2, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Remote Compromise of Oracle PeopleSoft Enterprise CS Student Financials
Weaknesses CWE‑284

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Remote Compromise of Oracle PeopleSoft Enterprise CS Student Financials
Weaknesses CWE‑284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Student Financials
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_student_financials:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Student Financials
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Student Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:43.617Z

Reserved: 2026-07-08T15:51:40.547Z

Link: CVE-2026-60602

cve-icon Vulnrichment

Updated: 2026-07-27T15:44:27.125Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function