Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: High Privilege Escalation / Full Compromise
Action: Immediate Patch
AI Analysis

Impact

PeopleSoft Enterprise PeopleTools (component SQR) is vulnerable to a flaw that allows a high privileged attacker with local access to take over the application. The vulnerability requires the attacker to log on to the infrastructure where PeopleSoft runs and to enlist a separate user for interaction, making exploitation difficult. If compromised, the attacker can exercise full control over PeopleSoft Enterprise PeopleTools and may affect other connected products because the flaw includes a scope change.

Affected Systems

Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 indicates moderate to high severity, with local attack, high privilege, required user interaction, and scope change. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Externally, a local privileged user with access to the infrastructure and the cooperation of another user is required to successfully exploit this vulnerability.

Generated by OpenCVE AI on September 17, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle PeopleSoft enterprise PeopleTools patch that 8.61 is not yet available, restrict local privileged login to the infrastructure hosting PeopleSoft Enterprise PeopleTools until a patch can be deployed, ensuring that only trusted administrators have access.
  • Review for all accounts that can access PeopleSoft and its SQR component, removing unnecessary high‑privilege rights.
  • Disable or restrict access to the vulnerable SQR component functions until a patch is available to reduce the exploitation surface.

Generated by OpenCVE AI on September 17, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via SQR Component Vulnerability in PeopleSoft Enterprise PeopleTools

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:49.288Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83016

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:59.418Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:08.423

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses