Junglewise Threat Intelligence

CVE-2026-60598: Oracle PeopleSoft Enterprise CS Student Records takeover in Research Tracking

CVE-2026-60598 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Student Records. Vendors: Oracle.

Executive brief

A vulnerability exists in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records. This software is used by educational institutions to manage student data and academic records. If exploited, a user with low-level access could take full control of the system, potentially leading to the theft of sensitive student information or the disruption of academic operations.

Technical details

A vulnerability in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records (version 9.2.38) allows for a complete system takeover. The flaw is accessible over the network via HTTP, though it is characterized by a high attack complexity, suggesting specific conditions or configurations must be met for successful exploitation. An attacker requires low-privileged credentials to initiate the exploit. Successful exploitation impacts the confidentiality, integrity, and availability of the affected system. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle PeopleSoft Enterprise CS Student Records 9.2.38

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD entry published

References

Related threats