Executive brief
Oracle PeopleSoft Enterprise HCM, a suite used for managing human resources and employee data, contains a vulnerability in its core component. An attacker could exploit this to modify or delete sensitive HR records and cause the system to crash, leading to a total loss of service. While the attack is difficult to execute, it does not require a username or password to initiate.
Technical details
A vulnerability exists in the Core component of Oracle PeopleSoft Enterprise HCM Human Resources version 9.2. The flaw allows an unauthenticated attacker with network access via TCP to compromise the application. Although the attack complexity is rated as high, a successful exploit enables unauthorized creation, deletion, or modification of critical data. Additionally, the vulnerability can be leveraged to cause a complete denial of service (DoS) by hanging or crashing the application. The CVSS 3.1 base score is 7.4, reflecting high impacts on integrity and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle PeopleSoft Enterprise HCM Human Resources 9.2
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD