Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation and full compromise of PeopleSoft Enterprise PeopleTools
Action: Immediate patch
AI Analysis

Impact

This vulnerability, identified as CWE-284, resides in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools. An attacker who has logged on locally to the infrastructure where PeopleSoft runs can exploit the flaw with high complexity and low privilege requirements. Successful exploitation leads to complete takeover of the PeopleSoft application, resulting in severe breaches of confidentiality, integrity and availability.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools is affected. The vulnerable product versions are 8.61 through 8.63, inclusive.

Risk and Exploitability

The CVSS v3.1 Base Score is 7.0 with a local attack vector, high attack complexity, low privileges, no user interaction, and impacts all core security dimensions. Despite a low EPSS of less than 1% and absence from the CISA KEV catalog, the potential for a full compromise exists for any organization that allows local users to access the PeopleSoft infrastructure. The reliance on local infrastructure credentials means the risk is confined to users with physical or network access to the application servers.

Generated by OpenCVE AI on September 17, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PeopleSoft Enterprise PeopleTools to a version outside the 8.61‑8.63 range or apply Oracle’s official security patch for CVE-2026-83015
  • Restrict physical or network access to the infrastructure hosting PeopleSoft; ensure only privileged administrators can log on to the application servers
  • If the Cube Manager feature is not critical, disable it or limit its usage, and monitor system logs for anomalous activity related to Cube Manager operations

Generated by OpenCVE AI on September 17, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Local Vulnerability in PeopleSoft Cube Manager Allows Full Compromise

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:54.679Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83015

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:57.160Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:08.303

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses