Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60666

CVE-2026-60666: PeopleSoft HCM Auth Bypass Vulnerability

CVE-2026-60666 is an authentication bypass vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources that allows unauthorized data access and modification. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-60666 Overview

CVE-2026-60666 affects the Oracle PeopleSoft Enterprise HCM Human Resources product, specifically its Security component. The flaw impacts supported version 9.2 and permits a low-privileged, network-adjacent attacker to compromise the application over Oracle Net. Successful exploitation allows unauthorized creation, deletion, or modification of critical data, plus complete read access to all PeopleSoft HCM Human Resources data. Oracle addressed the issue in the July 2026 Critical Patch Update.

Critical Impact

Authenticated attackers with network access can achieve full read and write access to sensitive HR data stored in PeopleSoft Enterprise HCM Human Resources.

Affected Products

  • Oracle PeopleSoft Enterprise HCM Human Resources version 9.2
  • Security component of PeopleSoft Enterprise HCM
  • Deployments exposing Oracle Net connectivity to reachable networks

Discovery Timeline

  • 2026-07-21 - CVE-2026-60666 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Oracle releases fix in Critical Patch Update

Technical Details for CVE-2026-60666

Vulnerability Analysis

The vulnerability resides in the Security component of Oracle PeopleSoft Enterprise HCM Human Resources 9.2. An attacker with a low-privileged account and network path to Oracle Net can leverage the flaw to bypass intended access controls. The impact covers both confidentiality and integrity of HCM data, while availability remains unaffected. Oracle categorizes the flaw as difficult to exploit, reflecting environmental preconditions such as specific configuration or timing needed for a successful attack. The EPSS probability is 0.236% with a percentile of 14.634, indicating current exploitation likelihood is low.

Root Cause

Oracle has not published detailed root cause information beyond identifying the affected Security component. The advisory indicates the vulnerability enables an authenticated attacker to reach protected data and functions that should be restricted based on the caller's assigned privileges. This behavior is consistent with a broken access control or authorization flaw within the HCM Security subsystem.

Attack Vector

Exploitation requires network access via Oracle Net and valid low-privileged credentials on the target PeopleSoft HCM instance. No user interaction is required, and the attack does not cross a security boundary between components. Once authenticated, the attacker interacts with the vulnerable Security component to read or modify HR records outside their authorized scope. See the Oracle Critical Patch Update - July 2026 for vendor-provided technical context.

Detection Methods for CVE-2026-60666

Indicators of Compromise

  • Unexpected read or write operations against HCM tables from low-privileged application accounts
  • Anomalous Oracle Net session activity originating from non-administrative hosts
  • PeopleSoft audit records showing privilege boundary changes on employee, payroll, or benefits data

Detection Strategies

  • Enable PeopleSoft audit logging on sensitive HR records and forward events to a centralized SIEM
  • Baseline normal query patterns per role and alert on deviations that touch critical HCM tables
  • Correlate Oracle Net connection logs with application-level authentication events to spot lateral or unauthorized access

Monitoring Recommendations

  • Monitor for bulk data reads or modifications initiated by accounts with minimal assigned permissions
  • Track failed and successful authorization checks within the PeopleSoft Security component
  • Review Oracle listener logs for unusual client hosts connecting to the HCM database instance

How to Mitigate CVE-2026-60666

Immediate Actions Required

  • Apply the Oracle July 2026 Critical Patch Update to all PeopleSoft Enterprise HCM Human Resources 9.2 deployments
  • Inventory user accounts with low privileges and validate they follow least-privilege principles
  • Restrict Oracle Net exposure so only trusted application tiers can reach the database listener

Patch Information

Oracle addressed CVE-2026-60666 in the Oracle Critical Patch Update - July 2026. Administrators should review the advisory for the exact bundle and patch identifiers applicable to their PeopleSoft HCM 9.2 environment and apply them in accordance with Oracle's guidance.

Workarounds

  • Limit inbound Oracle Net traffic to specific application server IP addresses using network access control lists
  • Rotate credentials for low-privileged PeopleSoft accounts and enforce strong password policies
  • Increase logging verbosity on the Security component until the patch is applied to improve post-incident review

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.