Executive brief
Oracle PeopleSoft Enterprise CS Student Records, a system used by educational institutions to manage student data and research tracking, contains a vulnerability that could allow an attacker to take full control of the application. While the attack is difficult to execute and requires high-level administrative privileges, a successful exploit would grant the attacker complete access to sensitive student records and research information. This could lead to significant data breaches, loss of data integrity, and disruption of academic operations.
Technical details
A vulnerability in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records (version 9.2.38) allows for a complete system takeover. The attack vector is network-based via HTTP, but the exploit complexity is rated as high, suggesting specific timing or environmental conditions are required. An attacker must already possess high-level administrative privileges to launch the attack. If successful, the exploit results in a total compromise of the application's confidentiality, integrity, and availability (C/I/A). The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise CS Student Records 9.2.38
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date