Junglewise Threat Intelligence

CVE-2026-60604: Oracle PeopleSoft Enterprise CS Campus Community security bypass in Security component

CVE-2026-60604 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Campus Community. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by higher education institutions to manage student data and campus operations. An attacker with basic user access could exploit this flaw to gain full control over the system. This could lead to the unauthorized access of sensitive student records, modification of institutional data, or disruption of campus services.

Technical details

A vulnerability in the Security component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows for a complete system takeover. The flaw is exploitable by a low-privileged attacker with network access via HTTP. While the attack complexity is rated as high, suggesting specific conditions or timing are required for success, a successful exploit results in a total loss of confidentiality, integrity, and availability. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats