Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-01-20
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and disclosure
Action: Apply patch
AI Analysis

Impact

The vulnerability exists in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker can send specially crafted HTTP requests to a publicly exposed interface, which may allow them to perform unauthorized updates, inserts, or deletes on database records, and to read a subset of data that should otherwise be protected. Although the description does not explicitly describe the issue as an XSS flaw, the cited CWE‑79 and the nature of the traffic imply a cross‑site scripting style weakness that is exploitable without authentication.

Affected Systems

PeopleSoft Enterprise PeopleTools versions 8.60, 8.61, and 8.62 are affected. These releases expose the Integration Broker API over HTTP without requiring user authentication, allowing remote traffic to reach the vulnerable code path.

Risk and Exploitability

The CVSS 3.1 base score of 6.1 reflects moderate severity, with limited impact on confidentiality and integrity and no availability impact. The EPSS score is less than 1 %, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation demands that an attacker send a malicious HTTP request and, because the attack requires a separate user to interact with the system, also depends on social‑engineering or human‑interaction tactics. The scope is potentially broader than PeopleSoft alone, as the breach may affect other integrated applications.

Generated by OpenCVE AI on April 18, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle PeopleSoft security update that covers versions 8.60, 8.61, and 8.62
  • Restrict inbound HTTP access to the Integration Broker endpoint to authorized IP ranges or VPNs
  • Configure application and web‑server logging to capture unexpected requests and investigate anomalies promptly

Generated by OpenCVE AI on April 18, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle PeopleSoft Integration Broker Allows Unauthorized Data Modification and Disclosure

Wed, 21 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-01-21T15:19:32.304Z

Reserved: 2026-01-05T18:07:34.712Z

Link: CVE-2026-21951

cve-icon Vulnrichment

Updated: 2026-01-21T15:19:28.732Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:58.110

Modified: 2026-01-29T20:59:17.973

Link: CVE-2026-21951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T15:45:04Z

Weaknesses