Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by educational institutions to manage student and campus data. An attacker could exploit this flaw over the network to gain unauthorized access to sensitive student or administrative records. This could result in the theft of critical data or the unauthorized modification and deletion of existing information, potentially disrupting campus operations and compromising student privacy.
Technical details
A vulnerability in the Security component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit is characterized as having high complexity, suggesting specific conditions or timing must be met for success. If successfully exploited, an attacker can achieve unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability primarily impacts data confidentiality and integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise CS Campus Community 9.2.38
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published in Oracle Critical Patch Update