Description
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland. While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Global Payroll for Switzerland component of Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland enables a low‑privilege attacker with network access over HTTP to create, delete, or modify critical payroll data. The flaw permits the attacker to gain unauthorized access to or complete control over all data within the affected system, leading to loss of confidentiality and integrity. The weakness is rooted in improper authorization controls in the application, allowing privileges that should be restricted.

Affected Systems

This issue affects Oracle Corporation PeopleSoft Enterprise HCM Global Payroll Switzerland, specifically version 9.2. No other versions or variants are listed as impacted; however, the description notes that the vulnerability could have a scope change that might affect additional PeopleSoft products.

Risk and Exploitability

The CVSS 3.1 base score of 8.2 reflects high confidentiality and integrity impact with a scope change, and an attack complexity of high, indicating that while effort is required, the risk remains significant. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild at present. Because the flaw is not listed in the CISA KEV catalog, there is no known active exploitation. The likely attack vector is over network HTTP, with the attacker requiring only low privileges. Successful exploitation would transition privileges and enable broad data manipulation.

Generated by OpenCVE AI on August 4, 2026 at 16:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2 released in the July 2026 CPU.
  • Restrict HTTP access to the application by enforcing a firewall or VPN that limits connections to trusted hosts.
  • Strengthen role‑based access controls within PeopleSoft, ensuring that low‑privileged accounts cannot perform create, delete or modify operations on payroll data, and regularly audit permissions.

Generated by OpenCVE AI on August 4, 2026 at 16:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Manipulation via HTTP in Oracle PeopleSoft Global Payroll Switzerland

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Manipulation via HTTP in Oracle PeopleSoft Global Payroll Switzerland

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege Remote Access in Oracle PeopleSoft HCM Global Payroll Switzerland
Weaknesses CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege Remote Access in Oracle PeopleSoft HCM Global Payroll Switzerland
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland. While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Hcm Global Payroll Switzerland
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_switzerland:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Hcm Global Payroll Switzerland
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Hcm Global Payroll Switzerland
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:21:17.668Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60665

cve-icon Vulnrichment

Updated: 2026-07-24T19:21:13.629Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses