PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60608 Oracle Corporation CVE debrief

A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid 9.2.38, allowing low-privileged attackers with logon access to compromise the system, leading to unauthorized data creation, deletion, modification, and read access. This vulnerability has a CVSS score of 6.1 and affects PeopleSoft Enterprise CS Financial Aid 9.2.38. The vulnerability is classified as a medium severity issue, and organizations using this product should prioritize patching to prevent potential data breaches. The debrief is based on the supplied source corpus and CVE record.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Financial Aid
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-05
Advisory published
2026-07-21
Advisory updated
2026-08-05

Who should care

Organizations using PeopleSoft Enterprise CS Financial Aid 9.2.38 should prioritize patching to prevent potential data breaches. This vulnerability affects low-privileged attackers with logon access, and its CVSS score is 6.1, indicating a medium severity. The vulnerability allows unauthorized data access and modification, and organizations should review their current deployments and assign an owner for follow-up.

Technical summary

The vulnerability, CVE-2026-60608, has a CVSS score of 6.1 and affects PeopleSoft Enterprise CS Financial Aid 9.2.38. It allows low-privileged attackers with logon access to compromise the system, potentially leading to unauthorized data access and modification. The vulnerability is classified as a medium severity issue, and organizations using this product should prioritize patching to prevent potential data breaches. The technical summary is based on the supplied source corpus and CVE record.

Defensive priority

Medium

Recommended defensive actions

  • Apply the vendor patch for PeopleSoft Enterprise CS Financial Aid 9.2.38
  • Restrict logon access to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes
  • Monitor for suspicious activity related to data creation, deletion, or modification
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-07-21T22:18:01.130Z and last modified on 2026-07-27T13:18:25.607Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects PeopleSoft Enterprise CS Financial Aid 9.2.38, and its CVSS score is 6.1, indicating a medium severity. The vulnerability allows low-privileged attackers with logon access to compromise the system, potentially leading to unauthorized data access and modification. The evidence provided is limited, and further verification is needed to determine the full scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60608 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60608

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60608 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60608

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.