Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle PeopleSoft Enterprise PeopleTools is vulnerable due to an issue in the PIA Core Technology component that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can lead to full takeover of the PeopleSoft instance, causing loss of confidentiality, integrity and availability. The vulnerability is classified with a CVSS 3.1 base score of 8.1, indicating a high‑severity flaw.

Affected Systems

The affected product is Oracle PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63. The vulnerability was found in the PIA Core Technology component of these releases.

Risk and Exploitability

The CVSS vector indicates an authenticated‑null penalty, no user interaction, and a single impact scope, meaning remote attackers can gain full control without credentials. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS score, the high CVSS score and remote nature of the flaw raise the likelihood of exploitation.

Generated by OpenCVE AI on August 21, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle PeopleSoft Enterprise PeopleTools update or patch that resolves the PIA Core Technology vulnerability as detailed in the Oracle security advisory referenced.
  • Restrict network access to the PeopleSoft HTTP endpoints to trusted IP ranges or apply firewall filtering to limit exposure to the public Internet.
  • Disable or limit the PIA Core Technology service if it is not required for legitimate business functions.
  • Ensure that authentication is required for all PIA Core Technology endpoints, disabling any anonymous access.

Generated by OpenCVE AI on August 21, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Full Control in PeopleSoft Enterprise PeopleTools

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Full Control in PeopleSoft Enterprise PeopleTools
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:33.442Z

Reserved: 2026-07-08T15:51:55.586Z

Link: CVE-2026-60742

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:10.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:41.440

Modified: 2026-08-21T13:45:57.657

Link: CVE-2026-60742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:30:05Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function