Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Panel Processor component of Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker with network access via HTTP can cause an update, insert or delete of data that the attacker is normally not authorized to modify, as well as read restricted data. The description explicitly states that successful attacks require human interaction from a person other than the attacker, indicating a social‑engineering component is needed. The impact is a compromise of data integrity and confidentiality for data exposed by the Panel Processor. This weakness is classified as CWE-285, Unauthorized Access.

Affected Systems

Oracle Corporation's PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected. All installations that expose the Panel Processor endpoint over HTTP are potentially vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates moderate severity, affecting confidentiality and integrity. The EPSS score of <1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness via crafted HTTP requests to the Panel Processor endpoint; they need network access and the cooperation of a user other than the attacker.

Generated by OpenCVE AI on August 5, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any available vendor patches or updates for PeopleSoft Enterprise PeopleTools 8.61 or 8.62.
  • Restrict HTTP access to the Panel Processor endpoint to trusted internal networks or enforce authentication before allowing access.
  • Configure PeopleSoft security settings to enforce least‑privilege permissions, disabling or tightly restricting update, insert, and delete operations exposed through the Panel Processor.
  • Monitor audit logs for suspicious data modification activity and review user access policies regularly.

Generated by OpenCVE AI on August 5, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Manipulation via Panel Processor in PeopleSoft PeopleTools

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Manipulation via Panel Processor in PeopleSoft PeopleTools

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Panel Processor in Oracle PeopleSoft PeopleTools
Weaknesses CWE-284
CWE-639

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Panel Processor in Oracle PeopleSoft PeopleTools
Weaknesses CWE-284
CWE-639

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:19:04.155Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60152

cve-icon Vulnrichment

Updated: 2026-07-23T15:18:56.825Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses