Junglewise Threat Intelligence

CVE-2026-60665: Oracle PeopleSoft Enterprise HCM data compromise in Global Payroll Switzerland

CVE-2026-60665 · Severity: high · CVSS 8.2 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle's PeopleSoft payroll software for Switzerland, which is used by organizations to manage employee compensation and tax compliance. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive payroll data or modify critical records. Such an attack could lead to the exposure of private employee information or the manipulation of financial data, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the Global Payroll for Switzerland component of Oracle PeopleSoft Enterprise HCM version 9.2. It is classified as a high-complexity exploit that requires network access via HTTP and low-level user privileges. The flaw allows an attacker to achieve unauthorized creation, deletion, or modification of critical data, as well as full read access to all accessible data within the component. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact security domains beyond the immediate PeopleSoft payroll environment. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats