CVE-2026-34280 is a vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources product, specifically within the Job Profile Manager component affecting version 9.2. The flaw allows attackers with high privileges and network access to compromise the system and manipulate critical HR data. The vulnerability has a CVSS 3.1 base score of 6.5 (Medium severity) and is easily exploitable via HTTP by a high-privileged network-based attacker without requiring user interaction. Successful exploitation could enable unauthorized creation, deletion, or modification of critical HR data, as well as unauthorized access to sensitive employee information across the PeopleSoft Enterprise HCM system. There is no evidence of active exploitation at this time. The vulnerability is not included in CISA's Known Exploited Vulnerabilities catalog, has no publicly available exploit code, and community attention remains minimal based on the low EPSS score of 0.00026. However, organizations running PeopleSoft 9.2 should implement patches promptly given the potential for data integrity and confidentiality breaches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.2CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.