Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability exists in the Tuxedo component of Oracle PeopleSoft Enterprise PeopleTools that specifically targets versions 8.61 through 8.63. The flaw permits an attacker who has logged into the host infrastructure with a low‑privileged account to compromise the PeopleSoft application. Successful exploitation results in full control of PeopleSoft Enterprise PeopleTools and consequently a serious confidentiality, integrity, and availability impact as described by the CVSS 3.1 base score of 7.0.

Affected Systems

Oracle Corporation PeopleSoft Enterprise PeopleTools versions 8.61, 8.62, and 8.63 are affected.

Risk and Exploitability

The vulnerability requires local access and a low‑privileged account, making exploitation more difficult than remote attacks but still feasible for a host user. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, indicating no known public exploitation at this time. The CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms the medium‑high severity as well as comprehensive impact if the flaw is exploited.

Generated by OpenCVE AI on August 21, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle PeopleSoft Enterprise PeopleTools to a version that removes the Tuxedo vulnerability (currently 8.64 or newer).
  • If upgrading is not immediately possible, place the PeopleSoft application in a highly restricted network segment or DMZ and limit all inbound traffic to only necessary services and privileged accounts.
  • Enforce strict local account controls on the host by removing or disabling any low‑privileged accounts that can log onto the infrastructure and enforce role‑based permissions to prevent unauthorized local execution.

Generated by OpenCVE AI on August 21, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Tuxedo Component in Oracle PeopleSoft PeopleTools

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:27.833Z

Reserved: 2026-07-08T15:51:55.600Z

Link: CVE-2026-60902

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:16.527Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:46.760

Modified: 2026-08-21T13:09:27.643

Link: CVE-2026-60902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function