Executive brief
A vulnerability exists in the Communication component of Oracle PeopleSoft Enterprise CS Campus Community, a platform used by educational institutions to manage student and staff interactions. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive campus data. This could lead to the exposure of private student records or other critical institutional information.
Technical details
An information disclosure vulnerability exists in the Communication component of Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation allows the attacker to bypass intended access controls to read critical data or gain complete access to all data accessible within the Campus Community module. The vulnerability is tracked as CVE-2026-60609 and has a CVSS 3.1 base score of 6.5, reflecting a high impact on confidentiality with no impact on integrity or availability.
Affected products
- Oracle PeopleSoft Enterprise CS Campus Community 9.2.38
Timeline
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update