Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle PeopleSoft Enterprise PeopleTools is vulnerable due to an issue in the PIA Core Technology component that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can lead to full takeover of the PeopleSoft instance, causing loss of confidentiality, integrity and availability. The vulnerability is classified with a CVSS 3.1 base score of 8.1, indicating a high‑severity flaw.

Affected Systems

The affected product is Oracle PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63. The vulnerability was found in the PIA Core Technology component of these releases.

Risk and Exploitability

The CVSS vector indicates an authenticated‑null penalty, no user interaction, and a single impact scope, meaning remote attackers can gain full control without credentials. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of EPSS data, the high CVSS score and remote nature of the flaw raise the likelihood of exploitation.

Generated by OpenCVE AI on August 18, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle PeopleSoft Enterprise PeopleTools update or patch that resolves the PIA Core Technology vulnerability as detailed in the Oracle security advisory referenced.
  • Restrict network access to the PeopleSoft HTTP endpoints to trusted IP ranges or apply firewall filtering to limit exposure to the public Internet.
  • Disable or limit the PIA Core Technology service if it is not required for legitimate business functions.

Generated by OpenCVE AI on August 18, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Full Control in PeopleSoft Enterprise PeopleTools
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:04.504Z

Reserved: 2026-07-08T15:51:55.586Z

Link: CVE-2026-60742

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:41.440

Modified: 2026-08-18T21:16:41.440

Link: CVE-2026-60742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:00:14Z

Weaknesses