Vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources
CVE-2026-60667

7.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60667?

A vulnerability exists in the PeopleSoft Enterprise HCM Human Resources product that allows an unauthenticated attacker with network access via TCP to compromise system integrity. This flaw enables unauthorized creation, deletion, or modification of critical data, impacting all accessible data within the application. Additionally, successful exploitation may lead to system hangs or crashes, affecting service availability. Organizations using PeopleSoft Enterprise HCM Human Resources version 9.2 should take immediate steps to apply available security patches to mitigate risk.

Affected Version(s)

PeopleSoft Enterprise HCM Human Resources 9.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.