Junglewise Threat Intelligence

CVE-2026-60534: Oracle Identity Manager Connector data compromise in PeopleSoft Applications

CVE-2026-60534 · Severity: high · CVSS 7.7 · Published 2026-07-21

Technologies: Oracle Identity Manager Connector (PeopleSoft Applications). Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Identity Manager Connector for PeopleSoft, a tool used to synchronize user identities between Oracle and PeopleSoft systems. A highly privileged attacker could exploit this flaw to gain full access to sensitive identity data, potentially allowing them to modify or delete critical user records. Because this component connects different systems, a successful attack could also impact the security of other integrated business applications.

Technical details

This vulnerability affects the PeopleSoft Applications component of the Oracle Identity Manager Connector. It is characterized by a high complexity (AC:H) and requires high privileges (PR:H) to exploit via the network using HTTP. The flaw allows for a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate security scope of the Identity Manager Connector. Successful exploitation can lead to unauthorized creation, deletion, or modification of all accessible data, as well as complete confidentiality loss. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users should refer to the Oracle July 2026 Critical Patch Update for remediation.

Affected products

  • Oracle Identity Manager Connector (PeopleSoft Applications) 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats