HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46849Published Modified CNA oracle

CVE-2026-46849: Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Other)

Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Other). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Student Financials accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an authorization or access-control vulnerability in the PeopleSoft Enterprise CS Student Financials component of Oracle PeopleSoft (version 9.2.38). A remote attacker with any valid low-privilege account can reach the affected service over HTTP and exploit the flaw without any additional victim interaction. Successful exploitation gives the attacker full read access to all student financial data and the ability to create, modify, or delete critical records within the application. No fix version has been published yet; HarborGuard is tracking the advisory and will surface a patched-image rebuild as soon as Oracle ships one.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-46849 is ingested from Oracle and upstream vulnerability feeds within minutes of publication and matched against all customer images, including custom-built images that layer PeopleSoft components. Any registry or CI pipeline image running the affected 9.2.38 version is flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 8.1 HIGH and weights it against each environment's compliance policy to determine urgency and routing. Triage tickets are delivered to the appropriate team inbox within each customer organization based on policy-defined ownership rules.

Available
Patch

Because no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. In the interim, HarborGuard surfaces the open advisory status in each environment's vulnerability queue so it remains visible and unresolved until a patch exists.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the PeopleSoft application over the network via HTTP; no local or physical access is required.

  • AuthenticationRequired

    A valid low-privilege account is sufficient; no administrative or elevated credentials are needed, but anonymous access alone is not enough.

  • Victim interactionNot required

    The attacker does not need to trick or involve any user; the exploit proceeds entirely through direct HTTP requests.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • Reads all student financial records accessible within the PeopleSoft application, including tuition balances, payment history, and financial aid data.
  • Modifies or deletes critical financial records, enabling fraudulent adjustments to student account data.
  • Creates unauthorized records or transactions within the Student Financials component, potentially affecting billing and reporting integrity.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46849, HarborGuard monitors the advisory on every ingest cycle and will automatically trigger a patched-image rebuild the moment an upstream fix is available. For customers with auto-remediation enabled, that rebuild will be followed by a regression-test run and a PR opened against affected workloads, with no manual intervention required. While the CVE remains unpatched, HarborGuard recommends applying network-policy controls to restrict HTTP access to the PeopleSoft Student Financials application to only trusted source IP ranges, enforcing the principle of least privilege on all application accounts to limit which users hold valid low-privilege credentials, and considering egress filtering to reduce lateral movement potential if a host is compromised. The advisory remains open and flagged in each environment's vulnerability queue until Oracle ships a fix.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / PeopleSoft Enterprise CS Student Financials
    9.2.38
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
References