Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Security component of Oracle PeopleSoft Enterprise PeopleTools and can be exploited by an attacker who already holds low‑privileged local access to the infrastructure where the application runs. By leveraging this weakness, the attacker can create, delete, modify or otherwise manipulate critical data, and gain unauthorized access to that data. The CVSS vector indicates access with high attack complexity, low privilege, no user interaction and a scope change that can affect other products within the same environment. Overall, the impact is a loss of confidentiality and integrity for all accessible data in the affected PeopleSoft installations.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected. No other product versions are listed as impacted in the current advisory.

Risk and Exploitability

The CVSS base score of 7.5 reflects a significant threat, and the EPSS score of 0.00106 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be able to log into the underlying system, meaning the risk is primarily internal. Because the vulnerability allows unauthorized data modification and access, internal attackers could achieve further lateral movement or impact other systems that rely on PeopleSoft data. While external exploitation appears unlikely without a prior compromise, the potential for internal damage is high and should be treated as such. Prompt mitigation through patching is recommended to eliminate this risk.

Generated by OpenCVE AI on August 21, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft Enterprise PeopleTools security patch that addresses this vulnerability, as issued in the Oracle security advisory for versions 8.61 and 8.62.
  • If the patch cannot be applied immediately, enforce least‑privilege user accounts and review PeopleSoft configuration settings to restrict creation, deletion, or modification of critical data to authorized roles.
  • Continuously monitor PeopleSoft audit logs for anomalous activity such as unauthorized data changes or the creation of new records, and investigate any such incidents promptly.

Generated by OpenCVE AI on August 21, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Data Modification in Oracle PeopleSoft Enterprise PeopleTools 8.61-8.62

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:25.646Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60975

cve-icon Vulnrichment

Updated: 2026-08-20T17:55:18.544Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:49.840

Modified: 2026-08-21T13:08:18.290

Link: CVE-2026-60975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function