Junglewise Threat Intelligence

CVE-2026-60614: Oracle PeopleSoft Enterprise CS Campus Community integrity and DoS vulnerability in Person Data

CVE-2026-60614 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Campus Community. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise CS Campus Community, a platform used by educational institutions to manage student and staff data, contains a vulnerability in its Person Data component. An attacker with basic user credentials could exploit this flaw to modify or delete critical records, access sensitive information, or cause a total system outage. While the attack is difficult to execute, a successful breach could significantly disrupt campus operations and compromise the integrity of institutional data.

Technical details

A vulnerability exists in the Person Data component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38). The flaw is exploitable by a low-privileged attacker with network access via HTTP, though Oracle notes the attack complexity is high. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of system data. Additionally, the vulnerability can be leveraged to cause a hang or repeatable crash, resulting in a complete denial of service (DoS). The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60614 was publicly released.

References

Related threats