PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60612 Oracle Corporation CVE debrief

A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. This MEDIUM severity vulnerability, with a CVSS score of 6.8, allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise CS Financial Aid
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Administrators and users of PeopleSoft Enterprise CS Financial Aid 9.2.38 should prioritize patching this vulnerability. Security teams should assess the risk and implement compensating controls if patches cannot be applied immediately.

Technical summary

The vulnerability is located in the Commonline Loans component of PeopleSoft Enterprise CS Financial Aid. It has a CVSS 3.1 Base Score of 6.8, indicating a MEDIUM severity level. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N), showing that the vulnerability allows for high impacts on confidentiality and integrity. The vulnerability is difficult to exploit and requires low privileges and network access via HTTP.

Defensive priority

Apply patches or updates as soon as possible. Implement network segmentation and access controls to limit exposure. Monitor for suspicious activity related to PeopleSoft Enterprise CS Financial Aid.

Recommended defensive actions

  • Apply patches or updates provided by Oracle for PeopleSoft Enterprise CS Financial Aid 9.2.38.
  • Implement network segmentation and access controls to limit exposure to the vulnerable component.
  • Monitor for suspicious activity related to PeopleSoft Enterprise CS Financial Aid.
  • Conduct regular security audits and vulnerability assessments.
  • Consider implementing compensating controls if patches cannot be applied immediately.

Evidence notes

The CVE record was published on 2026-07-21T22:18:01.573Z and was last modified on 2026-07-27T17:16:38.083Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:01.573Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.