Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise HCM, a suite used by organizations to manage human resources and employee data. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive personnel records or modify critical HR data. Such an incident could lead to the exposure of private employee information or the corruption of organizational records.
Technical details
This vulnerability affects the Security component of Oracle PeopleSoft Enterprise HCM Human Resources version 9.2. It is classified as a difficult-to-exploit flaw that requires the attacker to have low-level privileges and network access via Oracle Net. An attacker who successfully exploits this vulnerability can achieve full confidentiality and integrity impacts, allowing for the unauthorized viewing, creation, deletion, or modification of all accessible data within the HCM suite. The vulnerability does not impact system availability. Patch information is typically found in Oracle's Critical Patch Update (CPU) advisories.
Affected products
- Oracle PeopleSoft Enterprise HCM Human Resources 9.2
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD published the CVE record