Executive brief
Oracle PeopleSoft Enterprise CS Student Records, a system used by educational institutions to manage student data and research tracking, contains a security vulnerability. An authorized user with low-level permissions can exploit this flaw over the network to gain full access to sensitive student records. This could lead to the unauthorized viewing, modification, or deletion of critical academic and personal data, potentially compromising institutional integrity and student privacy.
Technical details
A vulnerability exists in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records version 9.2.38. The flaw is classified as easily exploitable and allows a low-privileged attacker with network access via HTTPS to compromise the system. Successful exploitation enables unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all accessible student records. The attack does not require user interaction and has high impacts on confidentiality and integrity, though it does not directly affect service availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise CS Student Records 9.2.38
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed