Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Integrity and availability compromise
Action: Patch Now
AI Analysis

Impact

A flaw in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools enables an attacker with low privileges over HTTP to create, delete, modify critical data, or trigger frequent crashes of the application. The vulnerability undermines integrity and availability, allowing unauthorized data manipulation and denial‑of‑service attacks, but does not affect confidentiality.

Affected Systems

Oracle PeopleSoft Enterprise PeopleTools, versions 8.61 through 8.63, are affected.

Risk and Exploitability

With a CVSS v3.1 base score of 8.1, this issue is rated high severity. The EPSS score of less than 1 % indicates a low overall exploitation probability in the wild, and it is not listed in the CISA KEVitable; an attacker who can reach the application over the network via HTTP can leverage it without needing elevated privileges or complex prerequisites.

Generated by OpenCVE AI on September 17, 2026 at 04:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑issued patch or upgrade to a version that is not affected by this vulnerability.
  • Restrict network access to Cube Manager by filtering inbound HTTP requests to trusted IP ranges and enforce strict authentication policies.
  • Disable the Cube Manager component if it is not required for business functions to eliminate the attack surface.
  • Enable comprehensive audit logging for Cube Manager operations and monitor logs for anomalous activity.

Generated by OpenCVE AI on September 17, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise PeopleTools Cube Manager Access Control Bypass Leading to Data Modification and Denial of Service

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:00.797Z

Reserved: 2026-08-31T15:40:57.330Z

Link: CVE-2026-83014

cve-icon Vulnrichment

Updated: 2026-09-16T15:54:51.678Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:08.180

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses