CVE-2026-46849: Oracle PeopleSoft CS Student Financials Data Access Vulnerability
A security flaw in Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38 allows someone with basic user credentials and network access to read, modify, or delete financial records they shouldn't be able to touch. The vulnerability requires an attacker to have valid login credentials but does not require any user interaction—once authenticated, the attacker can exploit it directly. This puts sensitive student financial data at significant risk.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.1 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-23
NVD description (verbatim)
Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Other). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Student Financials accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46849 is an improper access control vulnerability (CWE-284) in PeopleSoft Enterprise CS Student Financials. The flaw permits low-privileged authenticated users to escalate their data access via HTTP requests without additional attack complexity. The CVSS 3.1 vector reflects network accessibility (AV:N), low attack complexity (AC:L), and low privilege requirements (PR:L) with high confidentiality and integrity impact but no availability impact. The vulnerability affects the product's component classified as 'Other,' indicating the issue spans a broad functional area rather than a single isolated module.
Business impact
Educational institutions relying on PeopleSoft for student financial management face exposure of personal financial information, tuition records, payment histories, and account balances. Beyond data exposure, attackers could alter financial records—changing account balances, refund amounts, or billing status—creating operational chaos, potential financial loss, and regulatory compliance violations. If affected systems serve multiple campuses or consortiums, the blast radius is correspondingly larger. Breach disclosure and remediation costs, coupled with institutional reputation damage, make this a high-priority risk.
Affected systems
Only PeopleSoft Enterprise CS Student Financials version 9.2.38 is confirmed affected. Organizations running this specific version should assume exposure. Verify your current version against your PeopleSoft deployment records. Confirm whether your instance is exposed to HTTP-based access from untrusted networks or whether network segmentation limits attack surface.
Exploitability
The vulnerability is exploitable by any user with valid network credentials. No zero-day complexity exists—an attacker with legitimate (even low-privilege) account access can craft HTTP requests to access or modify data outside their intended scope without bypassing multi-factor authentication or additional approval steps. This is categorized as 'easily exploitable' by Oracle, meaning the barrier to weaponization is low.
Remediation
Apply the security patch from Oracle when released. Oracle's June 2026 security bulletin provides updated build numbers and patches for affected versions. Until patching, implement compensating controls: restrict network access to PeopleSoft via IP allowlist or VPN, enforce role-based access control at the application level, enable detailed audit logging on all data modification events, and monitor for unusual data access or deletion patterns by low-privilege accounts.
Patch guidance
Monitor Oracle's PeopleSoft security advisories for version 9.2.38 patches. Apply patches in a controlled manner—test in a staging environment first to confirm compatibility with your customizations and integrations. Verify against the vendor advisory for exact patch version numbers and installation procedures. Prioritize patching higher because the issue is easily exploitable by internal users. Establish a maintenance window to minimize disruption to students and finance staff.
Detection guidance
Enable HTTP request logging at the application and web server level. Look for low-privilege user accounts making HTTP requests to financial data endpoints they typically do not access. Track modifications to critical financial fields (balances, refund amounts, scholarship amounts) when initiated by accounts that should not possess that authority. Correlate login events with unusual data access timing. Use SIEM rules to flag bulk data read operations from low-privilege sessions, particularly outside normal business hours.
Why prioritize this
This vulnerability combines high CVSS score (8.1), ease of exploitation (low complexity, low privilege required), and high-value target data (financial records). It does not yet appear on CISA's Known Exploited Vulnerabilities catalog, but the easily exploitable nature means public proof-of-concept or active exploitation could emerge quickly once awareness spreads. Internal threat actors and compromised accounts pose immediate risk. Educational institutions typically have large populations of low-privileged users (students, staff), multiplying the attack surface. Patch as soon as possible.
Risk score, explained
CVSS 8.1 (HIGH) reflects network accessibility, low attack complexity, low privilege requirement, high confidentiality impact, and high integrity impact. The score does not assume active exploitation in the wild, but the 'easily exploitable' description and absence of user interaction (UI:N) elevate practical risk. Real-world severity is amplified by the sensitivity of financial data, the number of potential internal attackers, and the operational impact of modified records.
Frequently asked questions
Do I need to be an administrator to exploit this vulnerability?
No. The vulnerability requires only low-privilege credentials—for example, a student or staff member with a standard login. An attacker does not need administrator or specialized access to trigger the flaw.
Does this vulnerability require multi-factor authentication to be bypassed?
The flaw is exploited post-authentication. If your PeopleSoft environment enforces MFA, an attacker would still need valid credentials (username and password, plus MFA code). However, once authenticated, the improper access control allows unauthorized data access without additional approval or validation steps.
Will network isolation protect us while we wait for a patch?
Partially. Restricting inbound HTTP access to PeopleSoft to trusted IP ranges, VPN gateways, or campus networks reduces the risk of external exploitation. However, insider threats—compromised internal accounts or malicious employees—can still exploit the vulnerability from within the network. Implement both network controls and application-level monitoring.
Is there a workaround if we cannot patch immediately?
No workaround eliminates the vulnerability entirely. Combine network segmentation, strict role-based access control enforcement, comprehensive audit logging, and continuous monitoring for suspicious activity. Schedule patching within two weeks if operationally feasible; the risk is too high to defer indefinitely.
This analysis is based on Oracle's official CVE description and security bulletin published June 2026. Patch version numbers and specific remediation steps should be verified against the authoritative Oracle PeopleSoft security advisory. Organizations should conduct internal risk assessment based on their network architecture, user base size, and data sensitivity. No exploit code or weaponized proof-of-concept is provided or endorsed. Testing of patches in non-production environments is strongly recommended before deployment to production systems. Consult your Oracle support contract and internal security policies for compliance and incident response procedures. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access