{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-46851: Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-46851","status":"final","version":"1","initial_release_date":"2026-06-16T19:27:32.140Z","current_release_date":"2026-06-16T19:27:32.140Z","revision_history":[{"date":"2026-06-16T19:27:32.140Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-46851 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-46851"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-46851"},{"category":"external","summary":"Oracle Advisory","url":"https://www.oracle.com/security-alerts/cspujun2026.html"}]},"product_tree":{"branches":[{"category":"vendor","name":"Oracle Corporation","branches":[{"category":"product_name","name":"PeopleSoft Enterprise CS Campus Community","branches":[{"category":"product_version","name":"9.2.38","product":{"name":"Oracle Corporation PeopleSoft Enterprise CS Campus Community 9.2.38","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle_corporation:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-46851","title":"Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)","notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1"]},"scores":[{"cvss_v3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"products":["CSAFPID-1"]}],"remediations":[{"category":"none_available","details":"No fixed version is published yet. Monitor the upstream advisory.","product_ids":["CSAFPID-1"]}]}]}