Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the PeopleSoft Enterprise CS Campus Community component that handles person data. It is an authorization flaw (CWE-284) that allows an attacker with low privileges who can reach the system over HTTP to create, delete, or modify critical records, read data beyond authorized scope, and trigger application hangs or crashes.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise CS Campus Community, version 9.2.38. No other versions or subcomponents are reported as affected. The issue specifically concerns the Person Data module.

Risk and Exploitability

The CVSS base score of 7.1 reflects moderate to high severity driven by the authorization weakness identified as CWE-284, which impacts confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known widespread attacks. Exploitation requires only low privileges and network access over HTTP, making the attack path relatively simple but still risky because it can compromise data integrity, availability, and, to a lesser extent, confidentiality.

Generated by OpenCVE AI on August 5, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft patch that addresses the authorization flaw for version 9.2.38, or upgrade to a non‑affected release.
  • Restrict HTTP access to the PeopleSoft application to known, trusted IP ranges or VPN users, blocking unauthenticated or low‑privileged traffic.
  • Enable comprehensive audit logging for create, update, and delete operations and monitor for abnormal application crashes or hangs to detect potential exploitation attempts.

Generated by OpenCVE AI on August 5, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Authorization flaw in Oracle PeopleSoft Enterprise CS Campus Community allows data manipulation and Denial of Service

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Denial of Service via HTTP in Oracle PeopleSoft Enterprise CS Campus Community
Weaknesses CWE-285

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Denial of Service via HTTP in Oracle PeopleSoft Enterprise CS Campus Community
Weaknesses CWE-285

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Campus Software Campus Community Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T16:19:54.106Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60614

cve-icon Vulnrichment

Updated: 2026-07-27T16:18:35.827Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:01.793

Modified: 2026-07-31T20:00:49.807

Link: CVE-2026-60614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses