Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the nVision component of Oracle PeopleSoft Enterprise PeopleTools. An attacker with network access over HTTP can exploit a design flaw that permits unauthorized use of application functionality. The flaw can be leveraged with minimal skill but requires that a non‑attacker user interacts with the system, after which the attacker can gain full control. This establishes unilateral loss of confidentiality, integrity and availability for the entire PeopleSoft instance. The weakness is consistent with improper access control issues that allow elevated user privileges to be abused.

Affected Systems

Oracle PeopleSoft Enterprise PeopleTools, versions 8.61 through 8.63, accessed via the PeopleTools nVision module. These are the only versions identified as vulnerable by the vendor. All other released versions are not listed as vulnerable.

Risk and Exploitability

The CVSS vector indicates network accessibility (AV:N), low attack complexity (AC:L), no privileges (PR:N), required user interaction (UI:R), and universal scope (S:U). The CVSS Base Score of 8.8 signals a high severity. The EPSS score of 0.00288 indicates a very low probability of exploitation. The lack of an exemption from the CISA KEV catalog indicates it is not yet known to be actively exploited. The required human interaction from another user introduces a barrier, yet the impact is severe enough that remediation is essential.

Generated by OpenCVE AI on August 21, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft Security Patch for versions 8.61‑8.63.
  • Restrict HTTP access to the PeopleSoft application using firewall rules or IP whitelist so that only trusted sources can reach the nVision component.
  • Continuously monitor login and access logs for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP takeover of Oracle PeopleSoft nVision component

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:26.745Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60967

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:17.533Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:49.387

Modified: 2026-08-21T13:08:48.380

Link: CVE-2026-60967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:00:13Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function