Executive Summary: PeopleSoft Security Focus (July 2026 CPU)
racle’s July 2026 Critical Patch Update (CPU) contains high-severity security vulnerabilities impacting key PeopleSoft enterprise modules, specifically the CS Campus Community and FIN Staffing Front Office products.
Organizations running these PeopleSoft Enterprise applications must prioritize the application of these security patches, as they expose critical functional components to remote exploitation via HTTP.
⚠️ SEVERE EXPOSURE WARNING: WEB ACCESSIBLE ENDPOINTS
Are these vulnerabilities remotely exploitable? YES.
The flaws in both CS Campus Community and FIN Staffing Front Office are exploitable over the network via HTTP. For FIN Staffing Front Office, the vulnerability requires no authentication, allowing malicious actors to remotely interact with and compromise the system if exposed to the internet or untrusted internal segments.
Key PeopleSoft Vulnerabilities Disclosed
1. CS Campus Community Takeover (CVE-2026-60594)
- CVSS v3.1 Base Score: 8.8 (High) —
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - The Threat: An easily exploitable vulnerability in the Integration and Interfaces component allows a low-privileged attacker with network access via HTTP to compromise the PeopleSoft Enterprise CS Campus Community product. Successful attacks can result in the complete takeover of the CS Campus Community environment.
- Affected Versions: PeopleSoft Enterprise CS Campus Community version 9.2.38.
2. FIN Staffing Front Office Unauthenticated Data Manipulation (CVE-2026-60593)
- CVSS v3.1 Base Score: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - The Threat: An easily exploitable vulnerability in the Staffing Front Office component allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all accessible data within the FIN Staffing Front Office module.
- Affected Versions: PeopleSoft Enterprise FIN Staffing Front Office version 9.2.
Recommended Mitigation Strategy & Interim Workarounds
- Apply CPU Patches (Primary Fix): Immediately download and apply the July 2026 Critical Patch Update for your respective PeopleSoft environments using Oracle Change Assistant.
- Interim Web Tier & WAF Rules: For unauthenticated flaws like CVE-2026-60593, configure Web Application Firewall (WAF) or reverse proxy rules to inspect and block unauthorized HTTP POST/PUT requests targeting Staffing Front Office handlers (
/psc/ps/EMPLOYEE/SA/c/STAFFING_FRONT_OFFICE.*). - Network & Subnet Isolation: Restrict access to PeopleSoft Internet Architecture (PIA) HTTP/HTTPS ports (e.g., 8000/8443) using firewall access control lists (ACLs) to ensure only authorized institutional IP ranges or VPN clients can reach Campus Community integration endpoints.
- Temporary Account & Feature Lockdown: If immediate patching is delayed, temporarily disable remote integration gateways or restrict low-privileged portal user roles associated with Campus Community self-service modules until patches are deployed.
📚 Official Documentation & Technical References
Need assistance auditing or patching your PeopleSoft environments? Schedule an Emergency Audit.