Executive brief
Oracle PeopleSoft Enterprise HCM is a comprehensive human resources management suite used by organizations to manage employee data and payroll. A vulnerability in the French Public Sector Specific component allows an unauthorized person to access or modify sensitive personnel information over the network. This could lead to the exposure of private employee records or unauthorized changes to critical HR data.
Technical details
A vulnerability exists in the French Public Sector Specific component of Oracle PeopleSoft Enterprise HCM Human Resources version 9.2. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for unauthorized read access to all accessible data (high confidentiality impact) and unauthorized update, insert, or delete access to a subset of data (low integrity impact). The vulnerability does not require user interaction and has no impact on system availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise HCM Human Resources 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published