Executive brief
A vulnerability exists in the Billing component of Oracle PeopleSoft Enterprise CS Student Financials, a system used by educational institutions to manage student accounts and tuition billing. An attacker with basic user access can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized modification of financial records, exposure of sensitive student data, or a complete disruption of the billing service.
Technical details
A high-severity vulnerability exists in the Billing component of Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38. The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in a complete takeover of the PeopleSoft Enterprise CS Student Financials environment, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60602 and was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise CS Student Financials 9.2.38
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory