Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported flaw exists in the Security component of PeopleSoft Enterprise CS Campus Community and allows an attacker to perform unauthenticated data creation, deletion, modification, and read operations over HTTP. The vulnerability permits unauthorized access to critical data, potentially exposing sensitive information and compromising data integrity, despite providing only low confidentiality impact as defined by the CVSS vector. An attacker could alter or delete data without authentication, leading to significant business disruption. The CVSS 3.1 Base Score of 6.5 indicates moderate severity with confidentiality changed low and integrity high, with no impact on availability.

Affected Systems

Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is affected. The flaw is tied to the Security component of the application, and only this release is impacted. Systems running this version without the forthcoming patch remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 signals a moderate risk, and the EPSS score of less than 1% indicates exploitation is unlikely in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Attackers would need network access to the application server’s HTTP interface and can exploit the flaw without any authentication or user interaction. Given the lack of higher AV or UI vectors, the attack surface is limited to network-facing endpoints, but any compromise of these endpoints could lead to unauthorized data manipulation.

Generated by OpenCVE AI on August 4, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft patch for CVE-2026-60617 released in the July 2026 security update
  • Restrict HTTP traffic to the PeopleSoft application by firewalling or VPN to only trusted internal networks
  • Enforce strict authentication and role-based access controls on all application endpoints to eliminate unauthenticated data access

Generated by OpenCVE AI on August 4, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Unauthorized Data Access in Oracle PeopleSoft Enterprise CS Campus Community
Weaknesses CWE-200

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Unauthorized Data Access in Oracle PeopleSoft Enterprise CS Campus Community
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T16:47:39.797Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60617

cve-icon Vulnrichment

Updated: 2026-07-27T16:44:23.559Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses