Executive brief
A vulnerability exists in Oracle PeopleSoft Enterprise CS Student Records, a system used by universities to manage student data and academic information. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive student records and critical institutional data. This could lead to a significant breach of student privacy and the exposure of confidential academic statistics.
Technical details
An information disclosure vulnerability exists in the Higher Ed Statistics Agency (UK HESA) component of Oracle PeopleSoft Enterprise CS Student Records version 9.2.38. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. A successful exploit allows the attacker to bypass confidentiality controls and gain unauthorized access to critical data or complete access to all accessible student records. The vulnerability is rated with a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no impact on integrity or availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Student Records 9.2.38
Timeline
- 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
- 2026-07-21: disclosed: CVE-2026-60605 was published to the NVD.