CVE-2026-46851: Oracle PeopleSoft Campus Community Unauthenticated Remote Code Execution
A vulnerability in Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows an unauthenticated attacker on the network to gain complete control of the system through an HTTP connection. While the vulnerability is rated as difficult to exploit, successful attacks result in full system compromise, including unauthorized access, data modification, and service disruption. No user interaction is required for exploitation.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.1 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-94
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-23
NVD description (verbatim)
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46851 is a code injection vulnerability (CWE-94) affecting PeopleSoft Enterprise CS Campus Community 9.2.38. The flaw resides in the Security component and permits unauthenticated remote code execution via HTTP. The attack has high attack complexity but requires no privileges or user interaction. The CVSS 3.1 score of 8.1 reflects the severe impact potential: complete confidentiality, integrity, and availability compromise. The network-accessible nature of the vulnerability combined with its ability to achieve full system takeover elevates risk despite the difficult exploitation requirements.
Business impact
Exploitation of this vulnerability could enable attackers to completely compromise campus community operations, including student records, enrollment data, and administrative functions. Financial impact includes potential ransom demands, mandatory incident response and forensics, regulatory notification costs, and reputational damage to the institution. Educational organizations depend on PeopleSoft for mission-critical enrollment and financial aid processing; service disruption directly impairs institutional operations.
Affected systems
Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is confirmed vulnerable. Organizations running this specific version on internet-facing or network-accessible deployments face direct risk. Legacy or non-standard deployment configurations should be audited to identify all instances. Verify your exact patch level against Oracle's advisory, as adjacent versions may or may not be affected.
Exploitability
The vulnerability is classified as difficult to exploit, indicated by high attack complexity in the CVSS vector. However, difficulty should not be conflated with impossibility. An unauthenticated attacker needs only network access and HTTP connectivity; no credentials, multi-factor authentication, or user interaction is required. The barrier to exploitation is technical, not procedural. Once an attacker identifies and reaches a vulnerable instance, the path to code execution exists. The absence of the vulnerability from CISA's Known Exploited Vulnerabilities catalog (as of the published date) suggests public exploits are not yet widely available, but this status is time-dependent and subject to change.
Remediation
Immediate action required: contact Oracle for available security patches for PeopleSoft Enterprise CS Campus Community 9.2.38 and apply them urgently. Until patching is feasible, implement network segmentation to restrict HTTP access to the vulnerable application from untrusted networks. Deploy Web Application Firewall (WAF) rules to detect and block suspicious HTTP requests to Security component endpoints. Monitor audit logs for unusual authentication or code execution attempts. Consider a temporary reduction in external accessibility if operationally viable.
Patch guidance
Verify the latest security patch version directly from Oracle's PeopleSoft security advisory for version 9.2.38. Apply patches in a pre-production environment first to validate application stability and integration integrity. Given the complete compromise potential, expedited patch deployment is warranted despite the difficult exploitation classification. Coordinate with Oracle support if patch availability or applicability questions arise for your deployment variant.
Detection guidance
Monitor HTTP traffic to PeopleSoft Campus Community endpoints for unusual requests, especially to Security-related components or endpoints that process dynamic code. Examine web server and application logs for patterns indicative of code injection: encoded payloads, script-like syntax in HTTP parameters, and requests from unexpected source IP ranges. Configure alerting for authentication anomalies and unexpected privilege escalations following HTTP requests. Host-based detection should flag unusual process execution spawning from the PeopleSoft application process. Network behavior analysis can identify data exfiltration following a successful compromise.
Why prioritize this
This vulnerability merits high priority despite being difficult to exploit. The combination of unauthenticated access, network reachability, and complete system takeover capability makes it a credible attack vector. Educational institutions operating PeopleSoft are lucrative targets for ransomware and data theft operations. The absence of public exploits provides a narrow window for remediation before the threat landscape shifts. Organizations should prioritize this above lower-severity vulnerabilities and treat patch deployment as urgent.
Risk score, explained
The CVSS 3.1 score of 8.1 (HIGH severity) reflects the maximum impact potential: complete loss of confidentiality, integrity, and availability. The score is appropriately elevated despite high attack complexity because unauthenticated network access and no user interaction lower the effective barrier to exploitation in real-world scenarios. The high score appropriately signals that successful exploitation is catastrophic, even if execution is technically challenging.
Frequently asked questions
How do I know if we're running version 9.2.38?
Check your PeopleSoft system properties or product release documentation. Access the application directly and navigate to Help > About PeopleSoft or review your deployed build files. Contact Oracle Support if you cannot determine your exact patch level. Document your findings for remediation planning.
Why is this vulnerability not on CISA's KEV list yet?
The Known Exploited Vulnerabilities catalog is updated when federal agencies or trusted partners confirm active, in-the-wild exploitation. The absence indicates no confirmed public exploits have been observed at scale—not that exploitation is impossible. Organizations should not delay remediation pending KEV inclusion. Threat actors may exploit the vulnerability before public disclosure of active campaigns.
Can network segmentation alone protect us until we patch?
Network segmentation significantly reduces but does not eliminate risk. If an attacker gains internal network access through phishing or lateral movement, segmentation may be bypassed. Segmentation is a valuable interim control but not a substitute for patching. Combine it with WAF rules, increased monitoring, and expedited patch planning.
What should we do if we suspect active exploitation?
Immediately isolate affected systems from the network, preserve forensic evidence (logs, memory, disk images), and engage your incident response team and law enforcement if warranted. Assume full system compromise and plan for account credential resets, data integrity reviews, and regulatory notification. Engage Oracle Support and a cybersecurity firm specializing in incident response.
This analysis is provided for informational purposes and does not constitute legal, compliance, or professional security advice. Organizations must verify all technical details, patch availability, and version applicability directly with Oracle and their system administrators. CVSS scores and vulnerability classifications are subject to change and should be re-evaluated as new information becomes available. No exploit code or detailed attack methods are provided in this document. Organizations should conduct independent risk assessments aligned with their specific deployment configurations and risk tolerance. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10904HIGHChrome V8 Sandbox Escape Remote Code Execution
- CVE-2026-10928HIGHScript Injection in Google Chrome Headless – CVSS 8.8 High Severity
- CVE-2026-11231HIGHChrome Safe Browsing Code Execution on macOS – Patch Now
- CVE-2026-11688HIGHChrome SVG Sandbox Escape RCE Vulnerability – Patch Urgently
- CVE-2026-1829HIGHContent Visibility for Divi Builder Plugin RCE (v4.02 and below)
- CVE-2026-24155HIGHNVIDIA NeMo Framework Code Injection Vulnerability (CVSS 7.8)
- CVE-2026-25856HIGHOpenBullet2 Authenticated Remote Code Execution Vulnerability
- CVE-2026-41249HIGHCoreShop GitHub Actions RCE via Malicious Pull Request