Executive brief
A vulnerability exists in Oracle PeopleSoft Enterprise CS Financial Aid, a system used by higher education institutions to manage student financial assistance. An attacker with existing low-level access to the server infrastructure can exploit this flaw to modify, delete, or create critical financial aid data. This could lead to significant data integrity issues and unauthorized access to sensitive student information.
Technical details
This vulnerability affects the Institutional Methodology Need Analysis component of Oracle PeopleSoft Enterprise CS Financial Aid version 9.2.38. It is classified as an 'easily exploitable' flaw that requires the attacker to have local logon access to the infrastructure where the application executes (Attack Vector: Local). A successful exploit by a low-privileged user can result in unauthorized creation, deletion, or modification of critical application data (High Integrity impact) and unauthorized read access to a subset of data (Low Confidentiality impact). The vulnerability does not appear to impact service availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Financial Aid 9.2.38
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory