Junglewise Threat Intelligence

CVE-2026-60594: Oracle PeopleSoft Enterprise CS Campus Community takeover via Integration and Interfaces

CVE-2026-60594 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Campus Community. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by higher education institutions to manage student data and campus operations. An attacker with basic user access can exploit this flaw over the network to take full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive student records and administrative data, potentially disrupting university operations.

Technical details

A vulnerability in the Integration and Interfaces component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected component. While the specific CWE is not identified in the advisory, the CVSS vector indicates no user interaction is required and the attack complexity is low. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60594
  • 2026-07-21: advisory: Included in Oracle July 2026 Critical Patch Update

References

Related threats