Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS Campus Community executes to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle PeopleSoft Enterprise CS Campus Community 9.2.38 allows an unauthenticated attacker who can reach the physical communications segment attached to the hardware where the application runs to compromise the system. Successful exploitation grants the attacker unauthorized access to critical data or, in the worst case, to all data accessible by the application, and the attacker can also insert, update or delete data. The weakness is an access control violation that leads to a high confidentiality impact and a low integrity impact as reflected in the CVSS vector.

Affected Systems

Oracle PeopleSoft Enterprise CS Campus Community 9.2.38 is the affected product. No other versions or vendor products are listed as affected.

Risk and Exploitability

The CVSS v3.1 base score is 5.9, indicating a moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is adjacent network, requiring physical proximity or network access to the server’s communication segment, and the exploit does not require user interface interaction or elevated privileges.

Generated by OpenCVE AI on August 4, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch or upgrade to a version that fixes the 9.2.38 vulnerability as stated in the vendor’s security alert.
  • Restrict physical and logical network access to the PeopleSoft server by implementing segmentation and firewall rules that allow traffic only on required ports and from trusted hosts.
  • Enable comprehensive logging of authentication attempts, data access, and database modifications, and monitor these logs for anomalous activity to detect potential exploitation early.

Generated by OpenCVE AI on August 4, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Physical Network in Oracle PeopleSoft Enterprise CS Campus Community

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Physical Network in Oracle PeopleSoft Enterprise CS Campus Community

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Adjacent Network Segment in Oracle PeopleSoft 9.2.38

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Adjacent Network Segment in Oracle PeopleSoft 9.2.38
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS Campus Community executes to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Cs Campus Community
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Cs Campus Community
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Cs Campus Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T13:56:38.031Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61103

cve-icon Vulnrichment

Updated: 2026-07-24T13:56:33.447Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control