Junglewise Threat Intelligence

CVE-2026-61103: Oracle PeopleSoft Enterprise CS Campus Community security bypass

CVE-2026-61103 · Severity: medium · CVSS 5.9 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Campus Community. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle's PeopleSoft Enterprise CS Campus Community, a platform used by educational institutions to manage student and campus data. An attacker with physical access to the local network segment could potentially gain unauthorized access to sensitive student records or modify campus data. While the attack is difficult to execute, a successful exploit could lead to a significant breach of student privacy or data integrity.

Technical details

This vulnerability affects the Security component of Oracle PeopleSoft Enterprise CS Campus Community, specifically version 9.2.38. It is classified as a difficult-to-exploit flaw that requires the attacker to be on the same physical communication segment (adjacent network) as the target hardware. No authentication or user interaction is required for exploitation. If successful, an attacker can achieve unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is tracked as CVE-2026-61103 and was disclosed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle PeopleSoft Enterprise CS Campus Community 9.2.38

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update

References

Related threats