Executive brief
A critical vulnerability has been identified in Oracle PeopleSoft Enterprise CRM, a suite of applications used by businesses to manage customer relationships and business processes. An unauthenticated attacker could remotely exploit this flaw to gain full control over the affected system, potentially leading to the theft of sensitive customer data or a complete disruption of business operations. Because this component is integrated with other systems, a successful attack could also allow the intruder to compromise additional connected software products.
Technical details
This vulnerability exists in the Common Objects component of Oracle PeopleSoft Enterprise CRM version 9.2.23. It is classified as a high-complexity attack (AC:H) that can be executed by an unauthenticated attacker over the network via HTTP. A successful exploit results in a scope change (S:C), meaning the attacker can impact components beyond the immediate security scope of the PeopleSoft CRM Common Objects. The ultimate impact is a complete takeover of the affected component, resulting in total loss of confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise CRM Common Objects 9.2.23
Timeline
- 2026-07-21: disclosed: Initial publication by Oracle and NVD.
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.