Insufficient Access Control in Oracle PeopleSoft Human Resources
CVE-2026-22006
5.4MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 April 2026
What is CVE-2026-22006?
A vulnerability has been identified in Oracle’s PeopleSoft Enterprise HCM Human Resources product, specifically in the Employee Snapshot component. This issue allows low-privileged attackers with network access via HTTP to perform unauthorized actions. Exploiting this vulnerability requires human interaction from a third party, but it can potentially allow attackers to update, insert, or delete sensitive data inaccessible to them initially. Furthermore, there is a risk for unauthorized reading of sensitive employee data, posing significant risks to data integrity and confidentiality across related systems.
Affected Version(s)
PeopleSoft Enterprise HCM Human Resources 9.2