Description
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Commonline Loans component of PeopleSoft Enterprise CS Financial Aid allows a low‑privileged attacker with standard HTTP access to create, delete, or modify critical data, and to read all data available through PeopleSoft. The vulnerability, classified as CVSS 3.1 vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N, indicates significant confidentiality and integrity impacts while availability is unaffected. The low privileges required mean that a threat actor does not need elevated system credentials to exploit the issue. This issue is an instance of CWE‑284, improper authorization, allowing unauthorized actions.

Affected Systems

Oracle PeopleSoft Enterprise CS Financial Aid, version 9.2.38, is the confirmed affected release. The vulnerability resides in the Commonline Loans component and is specific to the HTTP interface exposed by the system.

Risk and Exploitability

The CVSS base score of 6.8 places the flaw in the medium severity range, yet the EPSS score of less than 1% indicates a low probability of exploitation in the wild as of this analysis. The vulnerability is not listed in CISA’s KEV catalog. The CVE data does not indicate that exploitation is actively occurring. Because the attack vector is purely over the network and requires only low privileges, organizations that expose PeopleSoft to external networks or have insufficient internal access controls should consider the risk high relative to their cybersecurity posture.

Generated by OpenCVE AI on August 5, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released in Oracle CPU July 2026, available at https://www.oracle.com/security-alerts/cpujul2026.html to fix the issue.
  • Restrict HTTP access to PeopleSoft by enforcing firewall rules, VPN restrictions, or IP‑based whitelisting to limit exposure to trusted administrative networks.
  • Review and tighten role‑based access controls within PeopleSoft to ensure users have only the permissions required for their function, and conduct an internal audit of data access patterns before and after applying the patch.

Generated by OpenCVE AI on August 5, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Commonline Loans HTTP Access in PeopleSoft Enterprise CS Financial Aid

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Commonline Loans HTTP Access in PeopleSoft Enterprise CS Financial Aid

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via HTTP in PeopleSoft Enterprise CS Financial Aid

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via HTTP in PeopleSoft Enterprise CS Financial Aid
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Financial Aid
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_financial_aid:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Financial Aid
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Financial Aid
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:41.328Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60612

cve-icon Vulnrichment

Updated: 2026-07-27T16:14:17.791Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:01.573

Modified: 2026-08-05T13:13:35.523

Link: CVE-2026-60612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses