CVE-2026-22019 is a vulnerability affecting Oracle PeopleSoft Enterprise HCM Shared Components version 9.2, specifically within the Person Search component. The flaw allows attackers to compromise sensitive human capital management data through network-based attacks, with potential impacts extending beyond the directly affected component. The vulnerability presents a medium-severity risk with a CVSS score of 5.4. It requires network access and low-level user privileges to exploit, with minimal attack complexity. However, successful exploitation requires social engineering or human interaction from another user. The vulnerability enables unauthorized read access to sensitive data and unauthorized modification or deletion of certain accessible records, posing notable confidentiality and integrity risks. This vulnerability currently shows minimal exploitation activity, with no public exploit code available and no inclusion on active vulnerability exploitation lists. The EPSS score of 0.00025 indicates very low probability of exploitation in the wild, and the vulnerability remains inactive on industry hot lists. However, organizations running PeopleSoft version 9.2 should prioritize patching due to the sensitivity of HCM data and the cross-product impact potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.2CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_shared_components:9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.