CVE-2026-60600 Overview
CVE-2026-60600 is a high-severity vulnerability in the Oracle PeopleSoft Enterprise FIN Project Costing product, specifically within the Projects component. The affected supported version is 9.2. An unauthenticated attacker with logon access to the infrastructure where PeopleSoft Enterprise FIN Project Costing runs can exploit this flaw. Successful exploitation requires human interaction from a user other than the attacker and can result in full takeover of PeopleSoft Enterprise FIN Project Costing, impacting confidentiality, integrity, and availability.
Critical Impact
Successful exploitation results in complete takeover of PeopleSoft Enterprise FIN Project Costing, compromising the confidentiality, integrity, and availability of financial project data.
Affected Products
- Oracle PeopleSoft Enterprise FIN Project Costing 9.2
- Component: Projects
- Deployments running on infrastructure hosting PeopleSoft FIN modules
Discovery Timeline
- 2026-07-21 - CVE-2026-60600 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Included in the Oracle Security Alert July 2026
Technical Details for CVE-2026-60600
Vulnerability Analysis
The vulnerability resides in the Projects component of Oracle PeopleSoft Enterprise FIN Project Costing version 9.2. Oracle categorizes the flaw as easily exploitable, meaning attackers do not require specialized conditions to trigger the issue. Exploitation requires local access to the infrastructure hosting the application and interaction from a legitimate user. Once exploited, the attacker gains control over the PeopleSoft Enterprise FIN Project Costing instance, affecting confidentiality, integrity, and availability at the highest level.
Because PeopleSoft FIN Project Costing manages sensitive financial project data, a takeover exposes budgets, cost allocations, and project records. Attackers can alter financial records, exfiltrate data, or disrupt project accounting workflows.
Root Cause
Oracle has not published detailed root cause information in the public advisory. The CVSS vector indicates a local attack vector with low complexity, no privileges required, but user interaction needed. The scope is unchanged, and impacts to confidentiality, integrity, and availability are all rated high. This pattern is consistent with vulnerabilities where a crafted input or artifact processed by a privileged user triggers execution or logic abuse within the application.
Attack Vector
The attacker must have logon access to the local infrastructure where PeopleSoft Enterprise FIN Project Costing executes. The attacker then delivers a malicious artifact that a separate legitimate user must interact with to trigger the flaw. This interaction chain converts local access plus social engineering into a full application takeover. No authentication is required for the attacker to stage the payload, which lowers the barrier for insider or foothold-based exploitation. Refer to the Oracle Security Alert July 2026 for vendor guidance.
Detection Methods for CVE-2026-60600
Indicators of Compromise
- Unexpected modifications to PeopleSoft FIN Project Costing configuration files or project records
- Unusual process execution or file drops on infrastructure hosting the Projects component
- Anomalous logon sessions from local accounts followed by user interaction events in PeopleSoft audit logs
- Unauthorized changes to project cost, budget, or allocation data
Detection Strategies
- Monitor PeopleSoft application and database audit logs for unauthorized data modifications in the Projects module
- Correlate local logon events with subsequent user activity in the FIN Project Costing interface
- Baseline normal administrative activity and alert on deviations involving the Projects component
Monitoring Recommendations
- Enable verbose auditing on PeopleSoft FIN modules and forward logs to a centralized SIEM
- Track file integrity on PeopleSoft application server directories
- Alert on new local accounts or privilege changes on servers hosting PeopleSoft
- Review Oracle Critical Patch Update advisories monthly for related PeopleSoft issues
How to Mitigate CVE-2026-60600
Immediate Actions Required
- Apply the fixes provided in the Oracle Security Alert July 2026 to all affected PeopleSoft Enterprise 9.2 instances
- Restrict local logon access to PeopleSoft infrastructure to authorized administrators only
- Educate users with access to FIN Project Costing about the risk of interacting with unverified artifacts
- Audit existing logon accounts on PeopleSoft servers and disable unused credentials
Patch Information
Oracle released patches for CVE-2026-60600 as part of the Oracle Critical Patch Update in July 2026. Administrators should download and apply the relevant patch for PeopleSoft Enterprise FIN Project Costing 9.2 from the vendor advisory. See the Oracle Security Alert July 2026 for patch identifiers and installation instructions.
Workarounds
- Enforce least-privilege access controls on the infrastructure hosting PeopleSoft FIN Project Costing
- Segment PeopleSoft servers from general user networks to limit local logon exposure
- Require multi-factor authentication for administrative access to PeopleSoft hosts
- Increase user awareness training to reduce the likelihood of interaction with attacker-supplied content
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

