Junglewise Threat Intelligence

CVE-2026-60606: Oracle PeopleSoft Enterprise CC data compromise in Common Application Objects

CVE-2026-60606 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise CC, a suite of business applications used for human resources and finance management, contains a critical vulnerability in its Common Application Objects component. An unauthenticated attacker can exploit this flaw over the network to gain full access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical corporate records, potentially leading to significant data breaches or operational disruption.

Technical details

A vulnerability exists in the Common Application Objects component of Oracle PeopleSoft Enterprise CC version 9.2. The flaw is classified as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized access to create, delete, or modify critical data, as well as complete read access to all data accessible by the component. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact system availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle PeopleSoft Enterprise CC Common Application Objects 9.2

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats