PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60612 Oracle Corporation CVE debrief

A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. This MEDIUM severity vulnerability, with a CVSS score of 6.8, allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Financial Aid
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-05
Advisory published
2026-07-21
Advisory updated
2026-08-05

Who should care

Administrators and users of PeopleSoft Enterprise CS Financial Aid 9.2.38 should prioritize patching this vulnerability. Security teams should assess the risk and implement compensating controls if patches cannot be applied immediately.

Technical summary

The vulnerability is located in the Commonline Loans component of PeopleSoft Enterprise CS Financial Aid. It has a CVSS 3.1 Base Score of 6.8, indicating a MEDIUM severity level. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N), showing that the vulnerability allows for high impacts on confidentiality and integrity. The vulnerability is difficult to exploit and requires low privileges and network access via HTTP.

Defensive priority

Apply patches or updates as soon as possible. Implement network segmentation and access controls to limit exposure. Monitor for suspicious activity related to PeopleSoft Enterprise CS Financial Aid.

Recommended defensive actions

  • Apply patches or updates provided by Oracle for PeopleSoft Enterprise CS Financial Aid 9.2.38.
  • Implement network segmentation and access controls to limit exposure to the vulnerable component.
  • Monitor for suspicious activity related to PeopleSoft Enterprise CS Financial Aid.
  • Conduct regular security audits and vulnerability assessments.
  • Consider implementing compensating controls if patches cannot be applied immediately.

Evidence notes

The CVE record was published on 2026-07-21T22:18:01.573Z and was last modified on 2026-07-27T17:16:38.083Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60612 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60612

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60612 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60612

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.