Summary
CVE-2026-60606 is a critical vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects version 9.2, disclosed as part of Oracle’s July 2026 Critical Patch Update. An unauthenticated, network-based attacker can exploit this flaw via HTTP — with no user interaction and low attack complexity — to gain full unauthorized read access to sensitive application data and perform unauthorized creation, deletion, or modification of critical data. The vulnerability carries a CVSS 3.1 base score of 9.1 (Critical).
Technical details
- Root cause: An exploitable flaw in the Common Application Objects component of Oracle PeopleSoft Enterprise that fails to enforce proper access controls for network-accessible HTTP endpoints, allowing unauthenticated requests to reach protected functionality.
- Trigger conditions: Exploitable remotely over the network via HTTP; requires no authentication, no user interaction, and no elevated privileges. Attack complexity is low.
- Attack vector: Network (HTTP), unauthenticated, directly reachable from the internet on exposed PeopleSoft deployments.
- Impact: High confidentiality impact — full unauthorized read access to all accessible application data; High integrity impact — unauthorized creation, deletion, or modification of critical data; No availability impact.
Affected software
- Oracle PeopleSoft Enterprise CC Common Application Objects, version 9.2
Severity
CVSS v3.1 Base Score: 9.1 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update patches for PeopleSoft Enterprise, as documented in Oracle’s official security advisory at https://www.oracle.com/security-alerts/cpujul2026.html.
- If immediate patching is not feasible: Restrict network-level access to PeopleSoft HTTP endpoints at the perimeter firewall or load balancer to ensure internet-facing PeopleSoft portals are isolated from untrusted networks until the patch can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

