Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PeopleSoft Enterprise CS Campus Community 9.2.38 contains a security flaw that allows an unauthenticated attacker to use the HTTP interface to read or modify data that should be protected. The vulnerability can lead to disclosure of confidential information and unauthorized updates, inserts or deletes, which may compromise business processes that rely on accurate PeopleSoft data. The weakness is identified as an improper access control flaw that grants users higher privileges than intended.

Affected Systems

The affected system is Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38. No other versions are reported as vulnerable in the current CNA data.

Risk and Exploitability

The CVSS v3.1 base score is 8.2, indicating a high severity of impact on confidentiality and moderate impact on integrity, while availability remains unaffected. The EPSS score is less than 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can reach the affected application over a public network via HTTP, and because no authentication is required they can execute the attack from any system that can connect to the web interface. The simplicity of the required traffic makes this an easily exploitable condition for adversaries with network access.

Generated by OpenCVE AI on August 4, 2026 at 17:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Oracle release notes and security advisories for any patch or update that addresses CVE-2026-60615.
  • Configure firewall or network segmentation rules to restrict HTTP traffic to PeopleSoft only to trusted internal IP ranges.
  • Monitor application logs for abnormal read or write activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control Exposing Sensitive Data via HTTP in Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Exposing Sensitive Data via HTTP in Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Untrusted HTTP Remote Access Vulnerability in Oracle PeopleSoft Campus Community
Weaknesses CWE-284

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Untrusted HTTP Remote Access Vulnerability in Oracle PeopleSoft Campus Community
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T16:41:32.799Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60615

cve-icon Vulnrichment

Updated: 2026-07-27T16:41:28.462Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses