Description
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the FM Need Analysis Calculator component of Oracle PeopleSoft Enterprise CS Financial Aid and permits a local attacker with low privileges to compromise the application. When successfully attacked, the vulnerability can lead to unauthorized access to critical data or complete access to all data handled by the application, impacting confidentiality solely.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise CS Financial Aid version 9.2.38 is affected. The vulnerability is limited to this specific release of the Financial Aid component.

Risk and Exploitability

The CVSS 3.1 base score of 5.5 reflects moderate severity, with local access, low privileges, no user interaction, and a single impact on confidentiality. The EPSS score is below 1 %, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must already have local, low‑privileged access to the infrastructure running PeopleSoft; they can then manipulate the component to read protected data. Once the component is abused, the attacker effectively bypasses the application’s authorization controls for sensitive information.

Generated by OpenCVE AI on August 4, 2026 at 03:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle patch that fixes CVE‑2026‑60607 for PeopleSoft Enterprise CS Financial Aid 9.2.38.
  • Restrict local logon privileges on the infrastructure hosting the application and enforce strong authentication for all users.
  • Monitor application and system logs for anomalous use of the FM Need Analysis Calculator and any unexpected data access patterns.

Generated by OpenCVE AI on August 4, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Attack Enables Unauthorized Data Access via FM Need Analysis Calculator

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Attack Enables Unauthorized Data Access via FM Need Analysis Calculator

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Local Access Vulnerability in Oracle PeopleSoft Enterprise CS Financial Aid
Weaknesses CWE-284

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Local Access Vulnerability in Oracle PeopleSoft Enterprise CS Financial Aid
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Financial Aid
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_financial_aid:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Financial Aid
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Financial Aid
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:27:37.606Z

Reserved: 2026-07-08T15:51:40.547Z

Link: CVE-2026-60607

cve-icon Vulnrichment

Updated: 2026-07-27T12:27:34.043Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor