Junglewise Threat Intelligence

CVE-2026-60669: Oracle PeopleSoft Enterprise HCM integrity vulnerability in Global Payroll Mexico

CVE-2026-60669 · Severity: medium · CVSS 5.9 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's PeopleSoft Enterprise HCM Global Payroll Mexico, a software component used by organizations to manage payroll operations in Mexico. A low-privileged user could exploit this flaw to modify or delete critical payroll data and cause partial service disruptions. While the attack is difficult to execute, it poses a risk to the integrity of financial records and the availability of payroll services.

Technical details

This vulnerability affects the Global Payroll for Mexico component of Oracle PeopleSoft Enterprise HCM version 9.2. It is classified as a difficult-to-exploit flaw that requires the attacker to have low-level privileges and network access via HTTP. Successful exploitation allows an attacker to perform unauthorized creation, deletion, or modification of critical data within the application. Additionally, the vulnerability can be used to trigger a partial denial of service (DoS), impacting the availability of the payroll system. The CVSS 3.1 base score is 5.9, reflecting high integrity impact and low availability impact, with no impact on confidentiality.

Affected products

  • Oracle PeopleSoft Enterprise HCM Global Payroll Mexico 9.2

Timeline

  • 2026-07-21: disclosed: Initial publication of the CVE record.
  • 2026-07-21: advisory: Oracle released security alert cpujul2026.html.

References