Junglewise Threat Intelligence

CVE-2026-60611: Oracle PeopleSoft Enterprise CS Campus Community information disclosure

CVE-2026-60611 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Campus Community. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by educational institutions to manage student and campus data. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive information. This could lead to the exposure of a subset of student or administrative data, potentially impacting privacy and regulatory compliance.

Technical details

A vulnerability in the Security component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows an unauthenticated attacker to compromise the system via HTTP. The flaw is categorized as easily exploitable and does not require user interaction. Successful exploitation results in unauthorized read access to a subset of data accessible by the Campus Community module. The vulnerability has a CVSS 3.1 base score of 5.3, reflecting a partial impact on confidentiality with no impact on integrity or availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats