Executive brief
Oracle PeopleSoft Enterprise CS Student Records, a system used by educational institutions to manage student data, contains a security vulnerability in its Australian Features component. An attacker with basic user access can exploit this flaw over the network to take full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive student records and academic data.
Technical details
A vulnerability exists in the Australian Features component of Oracle PeopleSoft Enterprise CS Student Records version 9.2.38. The flaw is categorized as easily exploitable and requires only low-privileged user credentials to execute over a network via HTTP. Successful exploitation allows an attacker to achieve a full compromise of the Student Records system, impacting confidentiality, integrity, and availability (CIA triad). While the specific CWE is not detailed in the advisory, the CVSS vector indicates no user interaction is required and the attack complexity is low. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Student Records 9.2.38
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date