CVE-2026-60666 Overview
CVE-2026-60666 affects the Oracle PeopleSoft Enterprise HCM Human Resources product, specifically its Security component. The flaw impacts supported version 9.2 and permits a low-privileged, network-adjacent attacker to compromise the application over Oracle Net. Successful exploitation allows unauthorized creation, deletion, or modification of critical data, plus complete read access to all PeopleSoft HCM Human Resources data. Oracle addressed the issue in the July 2026 Critical Patch Update.
Critical Impact
Authenticated attackers with network access can achieve full read and write access to sensitive HR data stored in PeopleSoft Enterprise HCM Human Resources.
Affected Products
- Oracle PeopleSoft Enterprise HCM Human Resources version 9.2
- Security component of PeopleSoft Enterprise HCM
- Deployments exposing Oracle Net connectivity to reachable networks
Discovery Timeline
- 2026-07-21 - CVE-2026-60666 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Oracle releases fix in Critical Patch Update
Technical Details for CVE-2026-60666
Vulnerability Analysis
The vulnerability resides in the Security component of Oracle PeopleSoft Enterprise HCM Human Resources 9.2. An attacker with a low-privileged account and network path to Oracle Net can leverage the flaw to bypass intended access controls. The impact covers both confidentiality and integrity of HCM data, while availability remains unaffected. Oracle categorizes the flaw as difficult to exploit, reflecting environmental preconditions such as specific configuration or timing needed for a successful attack. The EPSS probability is 0.236% with a percentile of 14.634, indicating current exploitation likelihood is low.
Root Cause
Oracle has not published detailed root cause information beyond identifying the affected Security component. The advisory indicates the vulnerability enables an authenticated attacker to reach protected data and functions that should be restricted based on the caller's assigned privileges. This behavior is consistent with a broken access control or authorization flaw within the HCM Security subsystem.
Attack Vector
Exploitation requires network access via Oracle Net and valid low-privileged credentials on the target PeopleSoft HCM instance. No user interaction is required, and the attack does not cross a security boundary between components. Once authenticated, the attacker interacts with the vulnerable Security component to read or modify HR records outside their authorized scope. See the Oracle Critical Patch Update - July 2026 for vendor-provided technical context.
Detection Methods for CVE-2026-60666
Indicators of Compromise
- Unexpected read or write operations against HCM tables from low-privileged application accounts
- Anomalous Oracle Net session activity originating from non-administrative hosts
- PeopleSoft audit records showing privilege boundary changes on employee, payroll, or benefits data
Detection Strategies
- Enable PeopleSoft audit logging on sensitive HR records and forward events to a centralized SIEM
- Baseline normal query patterns per role and alert on deviations that touch critical HCM tables
- Correlate Oracle Net connection logs with application-level authentication events to spot lateral or unauthorized access
Monitoring Recommendations
- Monitor for bulk data reads or modifications initiated by accounts with minimal assigned permissions
- Track failed and successful authorization checks within the PeopleSoft Security component
- Review Oracle listener logs for unusual client hosts connecting to the HCM database instance
How to Mitigate CVE-2026-60666
Immediate Actions Required
- Apply the Oracle July 2026 Critical Patch Update to all PeopleSoft Enterprise HCM Human Resources 9.2 deployments
- Inventory user accounts with low privileges and validate they follow least-privilege principles
- Restrict Oracle Net exposure so only trusted application tiers can reach the database listener
Patch Information
Oracle addressed CVE-2026-60666 in the Oracle Critical Patch Update - July 2026. Administrators should review the advisory for the exact bundle and patch identifiers applicable to their PeopleSoft HCM 9.2 environment and apply them in accordance with Oracle's guidance.
Workarounds
- Limit inbound Oracle Net traffic to specific application server IP addresses using network access control lists
- Rotate credentials for low-privileged PeopleSoft accounts and enforce strong password policies
- Increase logging verbosity on the Security component until the patch is applied to improve post-incident review
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

