Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An easily exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an attacker who can reach the system via HTTP to achieve high privileged compromise and takeover of the application. The flaw provides full control over confidentiality, integrity, and availability, resulting in a complete loss of the application’s security posture.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools product, specifically versions 8.61 through 8.63, is affected. Users running these releases are exposed to the risk.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 places this issue in the high severity range. With no EPSS data available and no listing in CISA KEV, the likelihood of current exploitation is uncertain, but the potential impact is severe. The attack vector is inferred to be remote over the network via HTTP, requiring an attacker with high privileges to execute the exploit.

Generated by OpenCVE AI on August 18, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for PeopleSoft Enterprise PeopleTools or upgrade to a version later than 8.63.
  • Limit direct HTTP access to the PeopleSoft servers to trusted IP ranges and enforce strict least‑privilege access controls.
  • Deploy a web application firewall or intrusion detection system to monitor and block anomalous PeopleCode requests.

Generated by OpenCVE AI on August 18, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title High Privilege Takeover via HTTP in Oracle PeopleSoft Enterprise PeopleTools
Weaknesses CWE-20
CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:17.375Z

Reserved: 2026-07-08T15:51:55.598Z

Link: CVE-2026-60883

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:46.303

Modified: 2026-08-18T21:16:46.303

Link: CVE-2026-60883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:45:16Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')