Junglewise Threat Intelligence

CVE-2026-60617: Oracle PeopleSoft Enterprise CS Campus Community security bypass in Security component

CVE-2026-60617 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Campus Community. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community, a software suite used by higher education institutions to manage student and campus data. An attacker could exploit this flaw to gain unauthorized access to student records, potentially allowing them to modify, delete, or view sensitive campus information. While the attack is difficult to execute, it does not require a username or password, posing a risk to data integrity and privacy.

Technical details

This vulnerability affects the Security component of Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38. It is classified as a security bypass or data manipulation flaw that can be exploited by an unauthenticated attacker over the network via HTTP. The attack complexity is rated as High, suggesting that successful exploitation may require specific timing or environmental conditions. If successful, the attacker can achieve unauthorized creation, deletion, or modification of all accessible data, as well as unauthorized read access to a subset of data. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-60617 was publicly released.

References

Related threats