PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60610 Oracle Corporation CVE debrief

A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft. The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Campus Community
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using PeopleSoft Enterprise CS Campus Community version 9.2.38 should prioritize patching this vulnerability to prevent potential unauthorized data access. This involves reviewing current deployments, identifying affected systems, and ensuring that patches are applied promptly to mitigate the risk of unauthorized data access.

Technical summary

The vulnerability, CVE-2026-60610, is in the Security component of PeopleSoft Enterprise CS Campus Community. It has a CVSS 3.1 Base Score of 5.9, indicating a medium severity. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N), showing that the vulnerability allows network attackers to access sensitive data without authentication or user interaction. Successful exploitation can lead to unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. The supported version that is affected is 9.2.38.

Defensive priority

Apply patches immediately, as this vulnerability allows unauthenticated access to sensitive data via network access.

Recommended defensive actions

  • Apply the patch from Oracle as soon as possible
  • Conduct a thorough inventory check to identify all instances of PeopleSoft Enterprise CS Campus Community version 9.2.38
  • Implement compensating controls such as monitoring for suspicious activity
  • Verify that no unauthorized access has occurred
  • Consider enhancing network security controls to limit access to PeopleSoft Enterprise CS Campus Community

Evidence notes

The CVE record was published on 2026-07-21T22:18:01.347Z and was last modified on 2026-07-27T13:18:25.903Z. The NVD entry is currently Undergoing Analysis. The vulnerability details are based on the information provided by the CVE.org and NVD.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:01.347Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.