Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L).
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Data Mover component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 through 8.63 (CWE‑284). An attacker who has high privileged access to the infrastructure where PeopleSoft runs can exploit the flaw to create, delete, or modify data and to gain unauthorized access to all data accessible through the application. The flaw also permits a partial denial of service. The attack requires the attacker to have elevated privileges and to obtain user interaction from a person other than the attacker, making it harder to exploit than a pure remote vulnerability but still achievable in an internal environment.

Affected Systems

The affected product is Oracle’s PeopleSoft Enterprise PeopleTools, specifically versions 8.61, 8.62, and 8.63. The Data Mover component is the source of the flaw. No other vendors or products are listed as directly impacted, though the description notes that the vulnerability may have a scope change that could affect additional PeopleSoft products when exploited.

Risk and Exploitability

The CVSS v3.1 Base Score of 7.2 reflects high confidentiality and integrity impact and medium availability impact, with a vector indicating limited attack surface (local) and high privilege required. Because the exploitation path needs a high‑privileged system account and a separate user interaction, the overall exploitability is lower than a remote attack but still represents a significant risk to environments where privileged accounts are present. The KEV database does not list this vulnerability and the EPSS score is < 1 %. Nonetheless, the combination of privilege escalation, scope change, and potential data tampering warrants prompt patching or mitigation.

Generated by OpenCVE AI on August 21, 2026 at 16:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update released in Oracle’s August 2026 PeopleSoft alert ( https://www.oracle.com/security-alerts/cspuaug2026.html) to upgrade Oracle PeopleSoft Enterprise PeopleTools to a non‑affected version.
  • If a patch cannot be applied immediately, disable or restrict use of the Data Mover component and enforce role‑based access to any remaining functions that rely on it.
  • Review and tighten privilege levels on all accounts with infrastructure access, ensuring that only necessary high‑ileged accounts exist and that they follow the principle of least privilege.
  • Monitor audit logs for unauthorized data modification or denial‑of‑service activity and investigate any anomalies promptly.

Generated by OpenCVE AI on August 21, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title High Privilege Data Manipulation Vulnerability in PeopleSoft Enterprise PeopleTools Data Mover

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Data Mover in Oracle PeopleSoft Enterprise PeopleTools 8.61‑8.63
Weaknesses CWE-285

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Data Mover in Oracle PeopleSoft Enterprise PeopleTools 8.61‑8.63
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:55:55.911Z

Reserved: 2026-07-08T15:51:55.598Z

Link: CVE-2026-60873

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:32.645Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:46.070

Modified: 2026-08-21T13:28:44.137

Link: CVE-2026-60873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:45:03Z

Weaknesses