Description
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools. An attacker with high privileges who has logged into the underlying infrastructure can exploit this flaw, resulting in the complete takeover of PeopleSoft Enterprise PT PeopleTools. The impact extends beyond confidentiality, integrity, and availability of the affected product due to the potential scope change to related applications.

Affected Systems

Oracle Corporation PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 are affected. No additional affected versions are listed in the current CNA data.

Risk and Exploitability

The CVSS base score of 8.2 indicates high severity, and the vector shows that the attack requires local access (AV:L), low attack complexity (AC:L), high privileges (PR:H) with no user interaction (UI:N). The EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw allows full control of the application and may affect other integrated products, it should be treated as a critical risk if the local infrastructure is compromised.

Generated by OpenCVE AI on June 17, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade PeopleSoft Enterprise PT PeopleTools to a version after 8.62 that contains the fix for this local privilege escalation vulnerability.
  • Restrict local logon access to the infrastructure hosting PeopleSoft Enterprise PT PeopleTools to essential personnel only, ensuring that no unnecessary accounts have high privileges.
  • Separate the deployment and production environments, and implement monitoring to detect any anomalous local activity within the PeopleSoft infrastructure.

Generated by OpenCVE AI on June 17, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Pt Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Pt Peopletools
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Pt Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:36:35.202Z

Reserved: 2026-04-01T20:03:40.836Z

Link: CVE-2026-35288

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T21:45:03Z

Weaknesses

No weakness.