PatchSiren cyber security CVE debrief
CVE-2026-60613 Oracle Corporation CVE debrief
A vulnerability was discovered in PeopleSoft Enterprise CS Student Records, a product of Oracle PeopleSoft. The affected component is Research Tracking, and the supported version is 9.2.38. This vulnerability is difficult to exploit and requires a high-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks can result in a takeover of PeopleSoft Enterprise CS Student Records. The vulnerability has a medium severity level with high impacts on confidentiality, integrity, and availability.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise CS Student Records
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Administrators and users of PeopleSoft Enterprise CS Student Records, particularly those with high privileges, should be aware of this vulnerability and take necessary precautions. This includes reviewing and applying patches or updates provided by Oracle, restricting network access, and monitoring for suspicious activity.
Technical summary
The vulnerability has a CVSS 3.1 Base Score of 6.6, indicating a medium severity level. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H), which means the vulnerability allows for high confidentiality, integrity, and availability impacts. This vulnerability is difficult to exploit and requires a high-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.
Defensive priority
Medium priority should be given to patching or mitigating this vulnerability, especially for high-privileged users.
Recommended defensive actions
- Apply the necessary patches or updates provided by Oracle.
- Restrict network access to PeopleSoft Enterprise CS Student Records.
- Monitor for suspicious activity.
- Implement compensating controls.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record was published on 2026-07-21T22:18:01.690Z and was last modified on 2026-07-27T17:16:38.187Z. The NVD entry is currently Undergoing Analysis. This information is based on the provided source corpus and may not reflect the current status of the vulnerability. Defenders should verify the current status and affected scope with Oracle. The vulnerability affects PeopleSoft Enterprise CS Student Records, specifically the Research Tracking component, version 9.2.38.
Official resources
-
CVE-2026-60613 CVE record
CVE.org
-
CVE-2026-60613 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:01.690Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.