Junglewise Threat Intelligence

CVE-2026-60612: Oracle PeopleSoft Enterprise CS Financial Aid data manipulation in Commonline Loans

CVE-2026-60612 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Financial Aid. Vendors: Oracle.

Executive brief

A vulnerability exists in the Commonline Loans component of Oracle PeopleSoft Enterprise CS Financial Aid, a system used by educational institutions to manage student financial assistance. An attacker with basic user credentials could potentially gain unauthorized access to sensitive financial aid records, allowing them to view, modify, or delete critical student data. While the attack is complex to execute, a successful breach could compromise the integrity of financial aid processing and expose private student information.

Technical details

This vulnerability affects the Commonline Loans component of Oracle PeopleSoft Enterprise CS Financial Aid version 9.2.38. It is classified as a high-complexity attack (AC:H) that requires the attacker to have low-level authenticated access (PR:L) to the network via HTTP. If successfully exploited, the attacker can achieve full confidentiality and integrity impacts, allowing for the unauthorized access, modification, or deletion of all data accessible to the PeopleSoft Enterprise CS Financial Aid application. The vulnerability does not impact system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise CS Financial Aid 9.2.38

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats