Executive brief
Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by educational institutions to manage student data and campus operations, contains a critical security vulnerability. An unauthenticated attacker could remotely exploit this flaw over the network to gain full control of the system. A successful attack could lead to the theft of sensitive student information, unauthorized modification of records, or a total disruption of campus services.
Technical details
A vulnerability in the Security component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows for remote code injection (CWE-94). The flaw is exploitable by an unauthenticated attacker via HTTP over the network. While the attack complexity is rated as high—suggesting specific conditions or configurations must be met—a successful exploit results in a complete compromise of confidentiality, integrity, and availability. This effectively allows an attacker to take over the affected PeopleSoft instance. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Campus Community 9.2.38
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle and NVD publication.