Description
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Mexico. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Mexico accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise HCM Global Payroll Mexico. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle PeopleSoft Enterprise HCM Global Payroll Mexico v9.2 allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical payroll data and to cause a partial denial of service. The flaw resides in the Global Payroll for Mexico component and results in high integrity impact and low availability impact, with no stated confidentiality impact.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise HCM Global Payroll Mexico product, version 9.2, is affected. The vulnerability is specific to the Global Payroll for Mexico component.

Risk and Exploitability

The CVSS 3.1 Base Score of 5.9 reflects moderate risk, with exploitability considered difficult and the EPSS score indicating a probability of exploitation less than 1%. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is over the network via HTTP, and the attacker requires only a low‑privilege account on the system. Successful exploitation could compromise data integrity and cause a partial denial of service.

Generated by OpenCVE AI on August 4, 2026 at 03:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle’s security advisory for an update or patch that addresses this vulnerability, or contact Oracle support for guidance on mitigation.
  • Restrict HTTP access to the payroll interface so that only trusted IP ranges and authenticated users can reach the service, and conduct regular integrity checks of payroll records to detect unauthorized changes.
  • Enforce role‑based access control for payroll functions, ensuring low‑privileged accounts have no rights to modify critical data, thereby limiting the impact of any successful attack.

Generated by OpenCVE AI on August 4, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Oracle PeopleSoft Global Payroll Mexico: Unauthorized Data Manipulation via HTTP

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Oracle PeopleSoft Global Payroll Mexico: Unauthorized Data Manipulation via HTTP

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attacks Enable Unauthorized Data Manipulation and Partial Denial in Oracle PeopleSoft Global Payroll Mexico

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attacks Enable Unauthorized Data Manipulation and Partial Denial in Oracle PeopleSoft Global Payroll Mexico
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Mexico. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Mexico accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise HCM Global Payroll Mexico. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle peoplesoft Enterprise Hcm Global Payroll Mexico
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_mexico:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Hcm Global Payroll Mexico
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Peoplesoft Enterprise Hcm Global Payroll Mexico
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:26:19.494Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60669

cve-icon Vulnrichment

Updated: 2026-07-24T19:26:14.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:07.867

Modified: 2026-08-03T12:38:59.923

Link: CVE-2026-60669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption