Executive brief
A security vulnerability exists in Oracle PeopleSoft's Common Application Objects, a component used for managing shared data and processes within the Enterprise resource planning (ERP) suite. An attacker with basic user access could trick another user into performing an action that grants the attacker full control over sensitive business data. This could lead to the unauthorized viewing, modification, or deletion of critical corporate information and potentially impact other integrated Oracle systems.
Technical details
This vulnerability affects the Common Application Objects component of Oracle PeopleSoft Enterprise CC, version 9.2. It is classified as a high-impact flaw (CVSS 8.7) that requires low administrative privileges and network access via HTTP. The attack requires human interaction (UI:R) from a victim other than the attacker, suggesting a Cross-Site Scripting (XSS) or similar request forgery class of vulnerability. A successful exploit results in a scope change (S:C), meaning the attacker can move beyond the privileges of the affected component to impact other parts of the PeopleSoft environment, leading to complete loss of confidentiality and integrity for accessible data. Patching information is typically found in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle PeopleSoft Enterprise CC Common Application Objects 9.2
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.