Junglewise Threat Intelligence

CVE-2026-46849: Oracle PeopleSoft Student Financials improper access control

CVE-2026-46849 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise CS Student Financials, a software suite used by educational institutions to manage student billing and financial records, contains a security vulnerability. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive student financial data. This could lead to significant data breaches, unauthorized financial changes, and loss of data integrity within the institution's records.

Technical details

An improper access control vulnerability (CWE-284) exists in the 'Other' component of Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended security restrictions to achieve unauthorized creation, deletion, or modification of all accessible data, as well as complete read access to sensitive information. The vulnerability has high impacts on confidentiality and integrity but does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise CS Student Financials 9.2.38

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats