What is CVE-2026-22019?
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Shared Components, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Shared Components accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Shared Components accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Timeline
- 2026-04-21Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Oracle Peoplesoft Enterprise Hcm Shared Components
Remediation Steps
- Apply SAP Security Note from March 2026 Patch Day.
- Restrict access to SAP NetWeaver administration interfaces.
- Review SAP system logs for unusual user activity.
- Coordinate with SAP Basis team for maintenance window.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of March 2026 (March 14–20)
Browse all tracked CVEs in the defend.network CVE database →