Executive brief
Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by educational institutions to manage student data and campus operations, contains a security vulnerability. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive student or institutional data. This could result in the theft of private information or the unauthorized modification and deletion of records, potentially disrupting campus operations and compromising data integrity.
Technical details
A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized access to all accessible data (High Confidentiality impact) and unauthorized update, insert, or delete access to some data (Low Integrity impact). The attack does not require user interaction or elevated privileges. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Campus Community 9.2.38
Timeline
- 2026-07-21: advisory: Initial advisory published by Oracle and NVD.