PatchSiren cyber security CVE debrief
CVE-2026-60614 Oracle Corporation CVE debrief
A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data, unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data, and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise CS Campus Community
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Administrators and security teams responsible for PeopleSoft Enterprise CS Campus Community installations, particularly those using version 9.2.38, should be aware of this vulnerability and take necessary actions to mitigate potential risks.
Technical summary
The vulnerability, CVE-2026-60614, has a CVSS 3.1 Base Score of 7.1, indicating high severity. It affects the Person Data component of PeopleSoft Enterprise CS Campus Community, version 9.2.38. Exploitation requires low privileges and network access via HTTP. Successful attacks can lead to unauthorized data modifications, reads, and potential system crashes. Administrators should focus on patching or mitigating this vulnerability to prevent significant data integrity and availability impacts. The vulnerability is difficult to exploit and allows low privileged attackers with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community, potentially resulting in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it can lead to significant data integrity and availability impacts.
Recommended defensive actions
- Apply the latest security patches from Oracle for PeopleSoft Enterprise CS Campus Community version 9.2.38.
- Implement network access controls to limit HTTP access to the vulnerable component.
- Monitor system logs for suspicious activities related to PeopleSoft Enterprise CS Campus Community.
- Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses.
- Enforce strong authentication and authorization mechanisms for users with low privileges.
Evidence notes
The CVE record was published on 2026-07-21T22:18:01.793Z and was last modified on 2026-07-27T17:16:38.337Z. The NVD entry is currently Undergoing Analysis. The vulnerability details are based on the information provided by Oracle and the CVE.org record.
Official resources
-
CVE-2026-60614 CVE record
CVE.org
-
CVE-2026-60614 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:01.793Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.