Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60668

CVE-2026-60668: Oracle PeopleSoft HCM Auth Bypass Flaw

CVE-2026-60668 is an authentication bypass vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources that enables unauthorized data access. This article covers the technical details, affected versions, and mitigations.

Published:

CVE-2026-60668 Overview

CVE-2026-60668 affects Oracle PeopleSoft Enterprise HCM Human Resources version 9.2, specifically the French Public Sector Specific component. The vulnerability allows an unauthenticated remote attacker to compromise the application over HTTP without user interaction. Successful exploitation grants unauthorized access to critical data and partial write access to PeopleSoft HCM records. Oracle disclosed the flaw in the July 2026 Critical Patch Update.

Critical Impact

Unauthenticated network attackers can gain complete read access to PeopleSoft HCM data and modify a subset of records, exposing employee, payroll, and public sector HR information.

Affected Products

  • Oracle PeopleSoft Enterprise HCM Human Resources 9.2
  • Component: French Public Sector Specific
  • Deployments exposing PeopleSoft HCM over HTTP

Discovery Timeline

  • 2026-07-21 - CVE CVE-2026-60668 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Addressed in the Oracle Critical Patch Update

Technical Details for CVE-2026-60668

Vulnerability Analysis

The vulnerability resides in the French Public Sector Specific component of Oracle PeopleSoft Enterprise HCM Human Resources 9.2. An attacker requires only network access over HTTP and no valid credentials. The attack complexity is low, and no user interaction is required. Oracle rates the confidentiality impact as high and the integrity impact as low, indicating full data exposure with limited write capability. Availability is not affected, so the application continues to operate during exploitation, which complicates detection.

Root Cause

Oracle has not publicly published the underlying flaw class in the advisory. The behavior described in the CVE — unauthenticated HTTP access producing broad read exposure and scoped write access — is consistent with a missing authentication or broken access control weakness in a country-specific HR module. Because the affected component is region-specific, deployments outside French Public Sector configurations may not expose the vulnerable code path.

Attack Vector

The attack vector is network-based over HTTP. An unauthenticated attacker sends crafted requests to the PeopleSoft web tier that reaches the French Public Sector Specific component. Successful requests return sensitive HR data such as employee records, personnel actions, and public sector attributes. The attacker can also submit requests that insert, update, or delete a subset of accessible records. Refer to the Oracle Critical Patch Update - July 2026 for vendor technical details.

Detection Methods for CVE-2026-60668

Indicators of Compromise

  • Unauthenticated HTTP requests to PeopleSoft HCM URLs referencing French Public Sector Specific components or pages.
  • Anomalous read volumes from web tier logs targeting HR data endpoints without prior authenticated session cookies.
  • Unexpected INSERT, UPDATE, or DELETE events in PeopleSoft HCM audit tables originating from unauthenticated or service accounts.
  • HTTP 200 responses to requests that would normally require a signed-in PS_TOKEN cookie.

Detection Strategies

  • Correlate web access logs with PeopleSoft application server logs to identify requests reaching HR components without a valid authenticated session.
  • Baseline typical request patterns for the French Public Sector module and alert on deviations in source IP, request rate, or URL patterns.
  • Monitor database audit logs for HR table access originating from application service accounts outside normal business workflows.

Monitoring Recommendations

  • Forward PeopleSoft web server, application server, and database audit logs to a centralized SIEM for correlation.
  • Enable PeopleSoft component-level auditing on tables in the French Public Sector Specific module.
  • Alert on outbound data transfers from PeopleSoft servers that exceed typical HR reporting baselines.

How to Mitigate CVE-2026-60668

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update for PeopleSoft Enterprise HCM Human Resources 9.2 as the primary remediation.
  • Restrict network access to the PeopleSoft web tier to trusted networks and VPN users until patching is complete.
  • Review web access logs for the past 90 days for unauthenticated requests targeting French Public Sector HR endpoints.
  • Rotate credentials and audit HR data changes if evidence of unauthorized access is found.

Patch Information

Oracle addressed CVE-2026-60668 in the July 2026 Critical Patch Update. Administrators should download and apply the applicable PeopleSoft HCM 9.2 bundle from My Oracle Support. Refer to the Oracle Critical Patch Update Advisory - July 2026 for the full patch matrix and installation prerequisites.

Workarounds

  • Disable or remove the French Public Sector Specific component if not required for business operations.
  • Place a web application firewall in front of PeopleSoft to block unauthenticated requests to the affected component paths.
  • Enforce network-level access controls that require authenticated VPN connectivity before reaching the PeopleSoft web tier.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.