PeopleSoft July 2026 Critical Patch Update: CS Campus Community & FIN Staffing Flaws

Technical breakdown of July 2026 PeopleSoft security patches, addressing high severity takeover and data manipulation vulnerabilities (CVE-2026-60594, CVE-2026-60593).

⚡ BLUF (Bottom Line Up Front) Summary

⚠️ Advisory Scope & Terms

The July 2026 Oracle Critical Patch Update addresses high-severity vulnerabilities in PeopleSoft, including a takeover flaw in CS Campus Community (CVE-2026-60594) and an unauthenticated data manipulation vulnerability in FIN Staffing Front Office (CVE-2026-60593). Immediate patching is required.

Environment & Prerequisites

ComponentVersion / Specification
Supported VersionsPeopleSoft Enterprise CS 9.2.38, FIN Staffing 9.2
Core ComponentIntegration and Interfaces / Staffing Front Office

Executive Summary: PeopleSoft Security Focus (July 2026 CPU)

racle’s July 2026 Critical Patch Update (CPU) contains high-severity security vulnerabilities impacting key PeopleSoft enterprise modules, specifically the CS Campus Community and FIN Staffing Front Office products.

Organizations running these PeopleSoft Enterprise applications must prioritize the application of these security patches, as they expose critical functional components to remote exploitation via HTTP.


⚠️ SEVERE EXPOSURE WARNING: WEB ACCESSIBLE ENDPOINTS

Are these vulnerabilities remotely exploitable? YES.
The flaws in both CS Campus Community and FIN Staffing Front Office are exploitable over the network via HTTP. For FIN Staffing Front Office, the vulnerability requires no authentication, allowing malicious actors to remotely interact with and compromise the system if exposed to the internet or untrusted internal segments.


Key PeopleSoft Vulnerabilities Disclosed

1. CS Campus Community Takeover (CVE-2026-60594)

  • CVSS v3.1 Base Score: 8.8 (High) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • The Threat: An easily exploitable vulnerability in the Integration and Interfaces component allows a low-privileged attacker with network access via HTTP to compromise the PeopleSoft Enterprise CS Campus Community product. Successful attacks can result in the complete takeover of the CS Campus Community environment.
  • Affected Versions: PeopleSoft Enterprise CS Campus Community version 9.2.38.

2. FIN Staffing Front Office Unauthenticated Data Manipulation (CVE-2026-60593)

  • CVSS v3.1 Base Score: 7.5 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • The Threat: An easily exploitable vulnerability in the Staffing Front Office component allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all accessible data within the FIN Staffing Front Office module.
  • Affected Versions: PeopleSoft Enterprise FIN Staffing Front Office version 9.2.

  1. Apply CPU Patches (Primary Fix): Immediately download and apply the July 2026 Critical Patch Update for your respective PeopleSoft environments using Oracle Change Assistant.
  2. Interim Web Tier & WAF Rules: For unauthenticated flaws like CVE-2026-60593, configure Web Application Firewall (WAF) or reverse proxy rules to inspect and block unauthorized HTTP POST/PUT requests targeting Staffing Front Office handlers (/psc/ps/EMPLOYEE/SA/c/STAFFING_FRONT_OFFICE.*).
  3. Network & Subnet Isolation: Restrict access to PeopleSoft Internet Architecture (PIA) HTTP/HTTPS ports (e.g., 8000/8443) using firewall access control lists (ACLs) to ensure only authorized institutional IP ranges or VPN clients can reach Campus Community integration endpoints.
  4. Temporary Account & Feature Lockdown: If immediate patching is delayed, temporarily disable remote integration gateways or restrict low-privileged portal user roles associated with Campus Community self-service modules until patches are deployed.

📚 Official Documentation & Technical References


Need assistance auditing or patching your PeopleSoft environments? Schedule an Emergency Audit.

⚠️INFORMATIONAL & TECHNICAL ADVISORY DISCLAIMER

The diagnostic methodologies, commands, and runbooks provided on DBPros.Net are published for informational and educational purposes only. They do not constitute customized professional consulting advice. Operating engineers and DBAs are solely responsible for securing pre-flight backups (RMAN, VM snapshots, LVM clones), validating changes in non-production staging environments, and adhering to organizational change-control policies. All content, scripts, and runbooks are provided "AS IS" without warranty of any kind, and DBPros.Net assumes no liability for system downtime, database corruption, data loss, or operational disruption. For complete advisory limitations and legal terms, view our full Terms of Service & Advisory Disclaimer.