Description
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise CC Common Application Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PeopleSoft Enterprise CC Common Application Objects in Oracle PeopleSoft contains an improper access control flaw (CWE‑284 and CWE‑601) that allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data. The flaw requires the attacker to obtain limited privileges and a secondary user’s interaction, so it is not a fully remote exploit. Once exploited, the attacker can gain unauthorized read/write access to all data handled by the application, compromising confidentiality and integrity.

Affected Systems

Oracle Corporation – PeopleSoft Enterprise CC Common Application Objects version 9.2 is impacted. The CNA lists only this product version; no other versions are reported as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 8.7 indicates high severity with substantial confidentiality and integrity impacts. The EPSS score is less than 1%, suggesting exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw from any remote host with HTTP access, but they need a low‑privileged account and require a human interaction from another user. Successful exploitation could allow the attacker to create, delete, or modify critical data and gain full access to all data accessible through the application.

Generated by OpenCVE AI on August 4, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for PeopleSoft Enterprise CC Common Application Objects 9.2 as issued by Oracle
  • Restrict HTTP access to the PeopleSoft application to trusted networks or enforce VPN/SSH tunnel requirements for remote users
  • Enforce strict role‑based access controls and audit all data modification actions for early detection of unauthorized activity

Generated by OpenCVE AI on August 4, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in PeopleSoft Enterprise CC Common Application Objects Enables Unauthorized Data Modification and Access Improper Access Control Enables Unauthorized Data Modification and Access in Oracle PeopleSoft

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in PeopleSoft Enterprise CC Common Application Objects Enables Unauthorized Data Modification and Access

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Access in Oracle PeopleSoft Enterprise CC Common Application Objects via Low Privilege HTTP Attack

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Access in Oracle PeopleSoft Enterprise CC Common Application Objects via Low Privilege HTTP Attack

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise CC Common Application Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cc Common Application Objects
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cc_common_application_objects:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cc Common Application Objects
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cc Common Application Objects
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:36.656Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61078

cve-icon Vulnrichment

Updated: 2026-07-24T14:05:55.959Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')