Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packaging). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Install and Packaging component of Oracle PeopleSoft Enterprise PeopleTools permits an unauthenticated attacker who can reach the system over HTTP to create, delete, or modify critical data, effectively compromising the confidentiality and integrity of all accessible PeopleSoft data. The likely attack vector is network access through the HTTP protocol, exploiting a weakness that bypasses authentication mechanisms required for these operations.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63, are susceptible. No other products or versions are indicated as affected in the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 reflects a high risk to confidentiality and integrity with high attack complexity and no privileges or user interaction required. The EPSS score indicates lower than 1% probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not be currently actively exploited but remains a significant risk. An attacker who successfully exploits this flaw can gain unauthorized access to or tampering of critical organizational data without needing to authenticate or interact with the system directly.

Generated by OpenCVE AI on August 21, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released for CVE-2026-60856 as detailed in the Oracle security advisory
  • Enforce network segmentation and firewall rules to block public HTTP access to the PeopleSoft Install and Packaging endpoints
  • Confirm that the installation and packaging interfaces are disabled or protected under role‑based access controls according to Oracle's recommended configuration

Generated by OpenCVE AI on August 21, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification in Oracle PeopleSoft PeopleTools Install and Packaging

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packaging). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:31.210Z

Reserved: 2026-07-08T15:51:55.596Z

Link: CVE-2026-60856

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:12.334Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:45.260

Modified: 2026-08-21T13:29:08.117

Link: CVE-2026-60856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:15:07Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function