Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw can be exploited easily, giving the attacker full control over the system. Successful exploitation results in a complete takeover, with confidentiality, integrity, and availability fully compromised, as reflected in the CVSS 3.1 Base Score of 9.8.

Affected Systems

This issue affects Oracle Corporation's PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63. The vulnerability is present in the Business Interlink component. Systems running these versions are at risk if the component is exposed to external or untrusted networks.

Risk and Exploitability

The CVSS score of 9.8 denotes critical severity, and the absence of an EPSS score indicates no current data on exploitation frequency, however the vulnerability remains high risk due to its remote nature and lack of authentication requirement. The exploitation pathway is straightforward: an attacker sends crafted HTTP requests to the vulnerable endpoint, bypassing authentication and executing code. Because the flaw is unauthenticated and no mitigations are in place, the risk is immediate for exposed systems. Oracle does not list this vulnerability in the CISA KEV catalog, but the critical score warrants urgent remediation.

Generated by OpenCVE AI on August 18, 2026 at 23:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch released in the August 2026 update to bring PeopleSoft Enterprise PeopleTools to a version newer than 8.63.
  • If a patch is not yet available, isolate the business interlink interface by restricting HTTP access to trusted IP addresses or by disabling the component entirely until a fix is deployed.
  • Enable and enforce proper authentication for all PeopleSoft entry points, ensuring that no module accepts unauthenticated requests. For temporary protection, configure web application firewalls to block suspicious HTTP requests targeting the interlink endpoint.

Generated by OpenCVE AI on August 18, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle PeopleSoft Enterprise PeopleTools via HTTP
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:12.188Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:44.280

Modified: 2026-08-18T21:16:44.280

Link: CVE-2026-60821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:00:04Z

Weaknesses