Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle PeopleSoft Enterprise CS Campus Community allows a low‑privileged attacker with network access over HTTP to compromise the application. If successfully exploited, the attacker can take full control of the system, causing loss of confidentiality, integrity, and availability. The weakness is classified in the Security component and carries a CVSS 3.1 base score of 7.5, indicating a high impact.

Affected Systems

The affected product is Oracle PeopleSoft Enterprise CS Campus Community, version 9.2.38. No other versions are listed as vulnerable in the current advisory.

Risk and Exploitability

The CVSS rating of 7.5 reflects significant risk, yet the EPSS score of less than 1 % suggests that exploitation in the wild is unlikely at present. The vulnerability is not listed in CISA's KEV catalog. Attackers must have remote HTTP access and a low‑privilege account. Organizations should treat it as a high‑priority risk until a patch is applied.

Generated by OpenCVE AI on August 2, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft patch released in July 2026 for version 9.2.38.
  • Restrict HTTP access to the PeopleSoft instance to trusted IP ranges or VPN endpoints.
  • Monitor audit logs and implement IDS rules to detect anomalous HTTP activity against the application.

Generated by OpenCVE AI on August 2, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability via HTTP Low‑Privileged Access in Oracle PeopleSoft Campus Community

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability via HTTP Low‑Privileged Access in Oracle PeopleSoft Campus Community
Weaknesses CWE-264
CWE-286

Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Takeover of Oracle PeopleSoft Enterprise CS Campus Community via HTTP
Weaknesses CWE-264
CWE-269

Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Takeover of Oracle PeopleSoft Enterprise CS Campus Community via HTTP
Weaknesses CWE-264
CWE-269

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:38.198Z

Reserved: 2026-07-08T15:51:40.547Z

Link: CVE-2026-60604

cve-icon Vulnrichment

Updated: 2026-07-27T15:50:04.324Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses