PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60598 Oracle Corporation CVE debrief

A high-severity vulnerability was found in the Research Tracking component of PeopleSoft Enterprise CS Student Records 9.2.38. The vulnerability has a CVSS score of 7.5 and can allow a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to system takeover. This CVE was published on 2026-07-21 and is still undergoing analysis in the NVD. The vulnerability is difficult to exploit, but successful attacks can result in system takeover. Organizations should prioritize patching to prevent potential system compromise.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Student Records
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using PeopleSoft Enterprise CS Student Records 9.2.38 should prioritize patching to prevent potential system compromise. Security teams and vulnerability management teams should review the CVE and NVD details for affected scope and vendor guidance. Additionally, operators and platform administrators should be aware of the potential impact on their systems and take necessary precautions.

Technical summary

The vulnerability is in the Research Tracking component of PeopleSoft Enterprise CS Student Records 9.2.38. It is difficult to exploit and requires low privileges and network access via HTTP. Successful attacks can lead to system takeover. The CVSS vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). This vulnerability has a high CVSS score of 7.5, indicating a high severity level. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to system takeover.

Defensive priority

High priority due to potential for system compromise and high CVSS score. Organizations should apply the patch from Oracle as soon as possible and restrict network access to the affected system.

Recommended defensive actions

  • Apply the patch from Oracle as soon as possible
  • Restrict network access to the affected system
  • Monitor for suspicious activity
  • Review and update access controls
  • Perform a thorough review of the system for any signs of compromise
  • Ensure that all necessary security patches are applied and up-to-date
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record was published on 2026-07-21T22:17:59.957Z and last modified on 2026-07-27T16:18:08.810Z. The NVD entry is currently Undergoing Analysis. Evidence is limited to CVE and NVD details. Defenders should verify PeopleSoft Enterprise CS Student Records 9.2.38 deployments and review Oracle guidance. The information provided is based on the CVE and NVD entries, which may not be comprehensive. Additional verification is necessary to ensure the accuracy of the vulnerability details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:59.957Z and has not been modified since then. The NVD entry is currently Undergoing Analysis