Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by higher education institutions to manage student data and campus operations. An attacker could exploit this flaw to gain unauthorized access to sensitive student or institutional information. While the attack is difficult to execute, a successful breach could result in the exposure of all data managed by the affected component.
Technical details
A vulnerability in the Security component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows an unauthenticated attacker with network access via HTTPS to compromise the system. The vulnerability is characterized by high attack complexity, suggesting that specific timing or environmental conditions must be met for a successful exploit. If exploited, the attacker can achieve unauthorized access to critical data or complete access to all data accessible within the Campus Community module. The vulnerability primarily impacts data confidentiality, with no reported impact on system integrity or availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Campus Community 9.2.38
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory