Junglewise Threat Intelligence

CVE-2026-61104: Oracle PeopleSoft Enterprise CS Student Records information disclosure in Research Tracking

CVE-2026-61104 · Severity: low · CVSS 3.7 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise CS Student Records. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise CS Student Records, a software suite used by educational institutions to manage student data and research tracking, contains a security vulnerability. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to a limited portion of student or research records. While the vulnerability is considered difficult to exploit, it poses a risk to the confidentiality of sensitive institutional data.

Technical details

A vulnerability exists in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records version 9.2.38. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the system. According to the CVSS metrics, the attack complexity is high, suggesting that successful exploitation may require specific environmental conditions or significant effort. If successfully exploited, an attacker can achieve unauthorized read access to a subset of data within the Student Records system. The vulnerability primarily impacts confidentiality, with no reported impact on system integrity or availability.

Affected products

  • Oracle PeopleSoft Enterprise CS Student Records 9.2.38

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.

References

Related threats