Insufficient Access Control in Oracle PeopleSoft Human Resources
CVE-2026-22006

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-22006?

A vulnerability has been identified in Oracle’s PeopleSoft Enterprise HCM Human Resources product, specifically in the Employee Snapshot component. This issue allows low-privileged attackers with network access via HTTP to perform unauthorized actions. Exploiting this vulnerability requires human interaction from a third party, but it can potentially allow attackers to update, insert, or delete sensitive data inaccessible to them initially. Furthermore, there is a risk for unauthorized reading of sensitive employee data, posing significant risks to data integrity and confidentiality across related systems.

Affected Version(s)

PeopleSoft Enterprise HCM Human Resources 9.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.