Description
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via Oracle Net to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 within the Security component. A low‑privileged attacker with network access over Oracle Net can exploit the flaw to create, delete or modify data and ultimately gain full access to all PeopleSoft Human Resources data. The impact includes confidentiality and integrity damage.

Affected Systems

Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 is affected. No other versions or products are listed.

Risk and Exploitability

The CVSS base score of 6.8 indicates moderate to high risk. The EPSS score of less than 1 % suggests exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attackers are expected to use a network vector via Oracle Net, requiring a low‑privileged account but no user interaction.

Generated by OpenCVE AI on August 2, 2026 at 21:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch for PeopleSoft Enterprise HCM 9.2 as reported in the Oracle security alert
  • Restrict Oracle Net access to the PeopleSoft server by limiting inbound connections to trusted IP addresses only
  • Review and tighten PeopleSoft access controls and privilege assignments to enforce least privilege

Generated by OpenCVE AI on August 2, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Access via Oracle Net in PeopleSoft 9.2

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Access via Oracle Net in PeopleSoft 9.2

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Oracle Net in PeopleSoft HCM 9.2

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Oracle Net in PeopleSoft HCM 9.2
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via Oracle Net to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Hcm Human Resources
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Hcm Human Resources
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Hcm Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:24:21.290Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60666

cve-icon Vulnrichment

Updated: 2026-07-24T19:24:14.179Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses