Summary
CVE-2026-60605 is a high-severity information disclosure vulnerability in Oracle PeopleSoft Enterprise CS Student Records version 9.2.38, affecting the Higher Ed Statistics Agency – UK HESA component. The flaw allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to sensitive student records data with no user interaction required. The vulnerability was disclosed as part of Oracle’s July 2026 Critical Patch Update (CPU), published on July 21, 2026.
Technical details
- Root cause: Inadequate access controls in the Higher Ed Statistics Agency – UK HESA component expose protected student records data to unauthenticated HTTP requests.
- Trigger conditions: An unauthenticated attacker with network access via HTTP can trigger the vulnerability under low-complexity conditions, with no user interaction required.
- Attack vector: Network (HTTP); no privileges or user interaction required.
- Impact: High confidentiality impact — unauthorized read access to sensitive student records data. No integrity or availability impact.
Affected software
- Oracle PeopleSoft Enterprise CS Student Records, version 9.2.38
Severity
CVSS v3.1 Base Score: 7.5 (HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU), which addresses CVE-2026-60605 for affected PeopleSoft Enterprise CS Student Records installations.
- If immediate patching is not feasible, restrict external network access to the PeopleSoft application to trusted IP ranges and enforce perimeter controls (e.g., firewall rules, WAF policies) to limit exposure of the Higher Ed Statistics Agency – UK HESA component until patching can be completed.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

