Summary
CVE-2026-60668 is a high-severity vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources (French Public Sector component), version 9.2, patched as part of Oracle’s July 2026 Critical Patch Update. An unauthenticated remote attacker with network access via HTTP can exploit this flaw to access critical HR data and modify certain system information — with no privileges and no user interaction required. The vulnerability carries a CVSS v3.1 base score of 8.2 (HIGH).
Technical details
- Root cause: The vulnerability resides specifically in the French Public Sector component of Oracle PeopleSoft Enterprise HCM Human Resources; Oracle has not disclosed a CWE or detailed technical root cause in the published advisory.
- Trigger conditions: Exploitable remotely over HTTP with no prior authentication and no user interaction required; attack complexity is rated Low.
- Attack vector: Network — the attacker requires only HTTP connectivity to a reachable PeopleSoft HCM instance.
- Confidentiality impact (HIGH): Successful exploitation can yield unauthorized access to critical HR data or complete access to all data accessible within the PeopleSoft Enterprise HCM Human Resources application.
- Integrity impact (LOW): The attacker can also modify certain system information within the application.
- Availability impact: None.
Affected software
- Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 (French Public Sector component)
Severity
- CVSS v3.1 Base Score: 8.2 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for July 2026, released July 21, 2026, which contains the fix for this vulnerability. Oracle PeopleSoft customers should follow Oracle’s standard CPU patching procedures available via My Oracle Support.
- If patching is delayed: Restrict network access to PeopleSoft HCM web-facing interfaces at the perimeter (firewall, WAF, or reverse proxy) to authorized IP ranges only. Disable or restrict access to the French Public Sector component if it is not operationally required.
- Additional context: Oracle’s July 2026 CPU addresses 84 vulnerabilities in PeopleSoft, 45 of which are remotely exploitable without authentication. Organizations should prioritize applying this CPU in full.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

