Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools, allowing an unauthenticated attacker with network access to HTTP to compromise the system. The vulnerability involves improper authorization (CWE-284) and missing authentication (CWE-306), enabling an attacker to subvert confidentiality, integrity, and availability, effectively granting full control of the installation. According to the reported CVSS v3.1 base score of 8.1, the impact is high.

Affected Systems

Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. The Integration Broker module is exposed to unauthenticated HTTP traffic, creating a direct attack surface for take‑over.

Risk and Exploitability

The attacker only needs connectivity to the HTTP port of the Integration Broker; no credentials or UI interaction are required. The base score of 8.1 reflects a severe threat, while the EPSS score indicates a very low (but non‑zero) exploitation probability of less than 1 %. This vulnerability is not listed in the CISA KEV catalog. The attack vector is a network‑based intrusion exploiting the lack of proper authentication and access controls on the Integration Broker service.

Generated by OpenCVE AI on August 21, 2026 at 14:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update that addresses the Integration Broker flaw as documented in the Oracle security alert
  • Restrict external HTTP access to the Integration Broker service if it is not required by business functionality
  • Implement network segmentation or firewall rules to limit exposure of the PeopleSoft Integration Broker to trusted IP ranges

Generated by OpenCVE AI on August 21, 2026 at 14:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated integration broker flaw allowing compromise of PeopleSoft Enterprise PeopleTools

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:32.324Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60831

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:11.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:44.630

Modified: 2026-08-21T13:36:53.123

Link: CVE-2026-60831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:00:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function