Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22019

20
FAUCET Score

CVE-2026-22019 is a vulnerability affecting Oracle PeopleSoft Enterprise HCM Shared Components version 9.2, specifically within the Person Search component. The flaw allows attackers to compromise sensitive human capital management data through network-based attacks, with potential impacts extending beyond the directly affected component. The vulnerability presents a medium-severity risk with a CVSS score of 5.4. It requires network access and low-level user privileges to exploit, with minimal attack complexity. However, successful exploitation requires social engineering or human interaction from another user. The vulnerability enables unauthorized read access to sensitive data and unauthorized modification or deletion of certain accessible records, posing notable confidentiality and integrity risks. This vulnerability currently shows minimal exploitation activity, with no public exploit code available and no inclusion on active vulnerability exploitation lists. The EPSS score of 0.00025 indicates very low probability of exploitation in the wild, and the vulnerability remains inactive on industry hot lists. However, organizations running PeopleSoft version 9.2 should prioritize patching due to the sensitivity of HCM data and the cross-product impact potential.

Impacted Technologies

VendorProductVersion(s)CPE
9.2CPE matchmatch criteria
cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_shared_components:9.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 2nd percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

oraclevendor investigatingvia nvd_reference
View patch

References

oracle.com / security-alerts/cpuapr2026.html
Vendor Advisory