Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Configuration Manager component of Oracle PeopleSoft Enterprise PeopleTools. It enables a low‑privileged attacker with network access to inject and execute arbitrary SQL commands. If successfully exploited, the attacker can gain full control over the PeopleSoft application, compromising confidentiality, integrity, and availability of organizational data.

Affected Systems

Affected systems are Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw is limited to the Configuration Manager function within these releases.

Risk and Exploitability

The CVSS score of 8.8 indicates a severe impact. The vector shows a network access requirement, low attack complexity, and low privileges required. EPSS is not listed, so exploitation probability remains unknown, but the high score signals a real threat. The vulnerability is not yet catalogued in CISA KEV, suggesting no known widespread exploits, yet the potential for rapid compromise warrants immediate attention.

Generated by OpenCVE AI on August 18, 2026 at 23:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for PeopleSoft Enterprise PeopleTools 8.61–8.63.
  • Restrict network access to the Configuration Manager component to trusted hosts only.
  • Reduce database permissions to the minimum required for the application to function.

Generated by OpenCVE AI on August 18, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low‑privileged Network Attacker Can Compromise PeopleSoft Enterprise PeopleTools via SQL
Weaknesses CWE-89

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:17.060Z

Reserved: 2026-07-08T15:51:55.598Z

Link: CVE-2026-60879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:46.190

Modified: 2026-08-18T21:16:46.190

Link: CVE-2026-60879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')