CVE-2026-22006 is a vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources (Employee Snapshot component), affecting version 9.2. The flaw allows low-privileged attackers with network access to compromise the application and potentially impact additional connected products through scope changes. The vulnerability has a CVSS 3.1 score of 5.4 (Medium severity) and is easily exploitable via HTTP. It requires low user privileges and user interaction from a third party, but carries moderate confidentiality and integrity impacts, allowing unauthorized read access and modification of sensitive HCM data. The attack vector is network-based with low complexity. Exploitation status indicates minimal current threat activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and shows an extremely low EPSS score of 0.00027, suggesting no active exploitation in the wild. Community attention appears limited, with an inactive status on exploit tracking lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.2CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.