SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60606 2026-07-21

CVE-2026-60606: Critical Unauthenticated Flaw in Oracle PeopleSoft Common Application Objects

"A critical, easily exploitable vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects allows unauthenticated network attackers to read and alter critical data, carrying a CVSS 3.1 base score of 9.1."

A critical, easily exploitable vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects allows unauthenticated network attackers to read and alter critical data, carrying a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-60606 is a vulnerability in the Common Application Objects component of Oracle PeopleSoft Enterprise CC Common Application Objects. According to Oracle's NVD record, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible to the affected component. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) confirms network attack vector, low complexity, no privileges required, and no user interaction; with high confidentiality and integrity impact and no availability impact.

Why It Matters

With a base score of 9.1 (CRITICAL) and a maximum exploitability sub-score of 3.9, this flaw requires no authentication and no user interaction. An attacker only needs network access over HTTP to reach a vulnerable instance. Because PeopleSoft frequently underpins enterprise HR, finance, and campus operations, the potential exposure of and tampering with critical business data makes this a high-priority fix. No active exploitation is confirmed in the supplied source material.

What's Vulnerable

Patch Status

The vulnerability is addressed in Oracle's Critical Patch Update for July 2026. Administrators should apply the fixes referenced in the Oracle Critical Patch Update Advisory (cpujul2026) as the required remediation. At the time of this record, the NVD entry status is "Received" (published 2026-07-21), and no CISA KEV entry accompanies the supplied data, so active exploitation is not confirmed.

Sources