Executive brief
Oracle PeopleSoft Enterprise CS Campus Community, a platform used by educational institutions to manage student and staff data, contains a vulnerability in its Integration and Interfaces component. A high-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive campus data. This could result in the unauthorized viewing, modification, or deletion of critical student and administrative records, potentially compromising the integrity of institutional data.
Technical details
An improper access control vulnerability (CWE-284) exists in the Integration and Interfaces component of Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38. The flaw is easily exploitable by a high-privileged attacker with network access via HTTPS. Successful exploitation allows the attacker to bypass intended security restrictions to create, delete, or modify all accessible data within the Campus Community module, as well as gain unauthorized read access to critical information. The vulnerability impacts confidentiality and integrity but does not affect service availability. Users are advised to refer to the Oracle June 2026 Critical Patch Update for remediation details.
Affected products
- Oracle PeopleSoft Enterprise CS Campus Community 9.2.38
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication of CVE-2026-46979