Description
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle PeopleSoft Enterprise CS Financial Aid that allows an attacker with low privileges who has logged into the underlying infrastructure to create, delete, or modify critical data. The flaw results in confidentiality and integrity impacts, with the CVSS 3.1 vector indicating a local attack versus local access privileges and no user interaction. The weakness corresponds to improper authorization, permitting unauthorized changes to system data.

Affected Systems

Oracle peopleSoft Enterprise CS Financial Aid, version 9.2.38, is affected.

Risk and Exploitability

The CVSS base score of 6.1 signals moderate severity, while an EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV registry. Attacks would require an attacker to have already gained local access to the infrastructure running PeopleSoft, making the risk contingent on the security of the operating environment but still significant enough to warrant remediation.

Generated by OpenCVE AI on August 4, 2026 at 17:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Oracle PeopleSoft Enterprise CS Financial Aid release that contains the fix, ensuring the version is newer than 9.2.38
  • Implement strict least‑privilege controls for users who can access the PeopleSoft environment to reduce the attack surface for low‑privileged actors
  • Enable logging and monitor for unauthorized creation, deletion, or modification of financial aid data to detect and mitigate potential misuse promptly

Generated by OpenCVE AI on August 4, 2026 at 17:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Bypass Allows Data Modification in PeopleSoft Enterprise CS Financial Aid

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Bypass Allows Data Modification in PeopleSoft Enterprise CS Financial Aid

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle PeopleSoft Enterprise CS Financial Aid
Weaknesses CWE-285

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle PeopleSoft Enterprise CS Financial Aid
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Financial Aid
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_financial_aid:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Financial Aid
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Financial Aid
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:26:58.093Z

Reserved: 2026-07-08T15:51:40.547Z

Link: CVE-2026-60608

cve-icon Vulnrichment

Updated: 2026-07-27T12:26:47.557Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:01.130

Modified: 2026-08-05T13:54:58.243

Link: CVE-2026-60608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses