PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60599 Oracle Corporation CVE debrief

A high-severity vulnerability was discovered in PeopleSoft Enterprise CS Student Records, specifically in the Research Tracking component of version 9.2.38. The vulnerability has a CVSS score of 8.1 and can allow an attacker with low privileges and network access via HTTPS to compromise the system and access critical data. This could lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Student Records
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using PeopleSoft Enterprise CS Student Records should prioritize patching this vulnerability to prevent potential attacks. The vulnerability's high severity and potential impact on critical data necessitate immediate attention from affected operators, platform administrators, vulnerability management teams, and security teams.

Technical summary

The vulnerability is located in the Research Tracking component of PeopleSoft Enterprise CS Student Records, version 9.2.38. An attacker with low privileges and network access via HTTPS can exploit this vulnerability to compromise the system and access critical data. The CVSS 3.1 Base Score is 8.1, indicating a high severity level with significant confidentiality and integrity impacts. Organizations should verify their deployments, review official advisories, and plan updates through change control. Compensating controls and log reviews for exposed assets are also recommended.

Defensive priority

High

Recommended defensive actions

  • Apply the patch provided by the vendor
  • Conduct a thorough review of system configurations and network access
  • Monitor system logs for suspicious activity
  • Implement additional security controls to prevent exploitation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-21T22:18:00.070Z and last modified on 2026-07-27T16:18:08.963Z. The NVD entry is currently Undergoing Analysis. This information is based on the supplied source corpus and may not reflect the current status of the vulnerability. Defenders should verify the affected scope and severity with the vendor and consider the limitations of the CVE and NVD data.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:00.070Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.