CVE-2026-60603

Oracle · PeopleSoft Enterprise CS Student Records

A vulnerability in the Australian Features component of Oracle PeopleSoft Enterprise CS Student Records allows a low privileged attacker to achieve full system takeover.

Executive summary

A high severity vulnerability in Oracle PeopleSoft Enterprise CS Student Records allows authenticated attackers to gain complete control of the application.

Vulnerability

This is an easily exploitable flaw in the Australian Features component that requires low level user privileges and network access via HTTP to execute. It allows a remote, authenticated attacker to compromise the integrity, availability, and confidentiality of the system.

Business impact

With a CVSS score of 8.8, this vulnerability poses a significant risk to the privacy and security of student records. Successful exploitation could lead to the unauthorized disclosure of sensitive personal identification information, violating compliance requirements and eroding trust in the institution.

Remediation

Immediate Action: Review the July 2026 Oracle Critical Patch Update advisory and apply all relevant security patches to version 9.2.38 immediately.

Proactive Monitoring: Audit access logs for the Student Records module to identify unusual access patterns or unauthorized queries originating from low privileged user accounts.

Compensating Controls: Implement strict network segmentation and WAF filtering to limit exposure of the Australian Features module to authorized internal traffic only.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Security teams should treat this vulnerability with high urgency. Ensure the latest Oracle security updates are applied to the affected environment, and conduct a thorough review of access controls to ensure that users are operating under the principle of least privilege.