PatchSiren cyber security CVE debrief
CVE-2026-60612 Oracle Corporation CVE debrief
A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. This MEDIUM severity vulnerability, with a CVSS score of 6.8, allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise CS Financial Aid
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Administrators and users of PeopleSoft Enterprise CS Financial Aid 9.2.38 should prioritize patching this vulnerability. Security teams should assess the risk and implement compensating controls if patches cannot be applied immediately.
Technical summary
The vulnerability is located in the Commonline Loans component of PeopleSoft Enterprise CS Financial Aid. It has a CVSS 3.1 Base Score of 6.8, indicating a MEDIUM severity level. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N), showing that the vulnerability allows for high impacts on confidentiality and integrity. The vulnerability is difficult to exploit and requires low privileges and network access via HTTP.
Defensive priority
Apply patches or updates as soon as possible. Implement network segmentation and access controls to limit exposure. Monitor for suspicious activity related to PeopleSoft Enterprise CS Financial Aid.
Recommended defensive actions
- Apply patches or updates provided by Oracle for PeopleSoft Enterprise CS Financial Aid 9.2.38.
- Implement network segmentation and access controls to limit exposure to the vulnerable component.
- Monitor for suspicious activity related to PeopleSoft Enterprise CS Financial Aid.
- Conduct regular security audits and vulnerability assessments.
- Consider implementing compensating controls if patches cannot be applied immediately.
Evidence notes
The CVE record was published on 2026-07-21T22:18:01.573Z and was last modified on 2026-07-27T17:16:38.083Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).
Official resources
-
CVE-2026-60612 CVE record
CVE.org
-
CVE-2026-60612 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:01.573Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.