PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60610 Oracle Corporation CVE debrief

A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft. The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Campus Community
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-31
Advisory published
2026-07-21
Advisory updated
2026-07-31

Who should care

Organizations using PeopleSoft Enterprise CS Campus Community version 9.2.38 should prioritize patching this vulnerability to prevent potential unauthorized data access. This involves reviewing current deployments, identifying affected systems, and ensuring that patches are applied promptly to mitigate the risk of unauthorized data access.

Technical summary

The vulnerability, CVE-2026-60610, is in the Security component of PeopleSoft Enterprise CS Campus Community. It has a CVSS 3.1 Base Score of 5.9, indicating a medium severity. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N), showing that the vulnerability allows network attackers to access sensitive data without authentication or user interaction. Successful exploitation can lead to unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. The supported version that is affected is 9.2.38.

Defensive priority

Apply patches immediately, as this vulnerability allows unauthenticated access to sensitive data via network access.

Recommended defensive actions

  • Apply the patch from Oracle as soon as possible
  • Conduct a thorough inventory check to identify all instances of PeopleSoft Enterprise CS Campus Community version 9.2.38
  • Implement compensating controls such as monitoring for suspicious activity
  • Verify that no unauthorized access has occurred
  • Consider enhancing network security controls to limit access to PeopleSoft Enterprise CS Campus Community

Evidence notes

The CVE record was published on 2026-07-21T22:18:01.347Z and was last modified on 2026-07-27T13:18:25.903Z. The NVD entry is currently Undergoing Analysis. The vulnerability details are based on the information provided by the CVE.org and NVD.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60610 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60610

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60610 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60610

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.