Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution leading to takeover
Action: Immediate patch
AI Analysis

Impact

The vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged attacker who can reach the system via HTTP to execute code or otherwise compromise the entire PeopleSoft application. The flaw results in complete loss of confidentiality, integrity and availability and can be used to take over the PeopleSoft system entirely. This is a high‑severity flaw identified as CVE‑2026‑83017 with a CVSS 3.1 base score of 8.8.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools, specifically the Report Distribution component. Affected versions have been listed as 8.61 through 8.63. The flaw impacts installations of those versions that expose the Report Distribution endpoint over the network.

Risk and Exploitability

The CVSS score of 8.8 indicates a high overall risk. The EPSS score of <1% suggests that, as of the last assessment, exploitation likelihood is very low, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the attack vector is inferred to be over a public or enterprise network via HTTP, allowing an attacker with low privileges on the network to trigger the vulnerability. Because the impact includes full takeover of the PeopleSoft application, the potential damage is severe, especially for organizations with sensitive data or critical business processes.

Generated by OpenCVE AI on September 20, 2026 at 13:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a version that removes the flaw (e.g., PeopleSoft 8.64 or newer).
  • If a patch is not yet available, block external HTTP access to the Report Distribution endpoint using firewall rules or network access control to limit connections to trusted hosts only.
  • Temporarily disable the Report Distribution feature in the PeopleSoft configuration until a patch is applied to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Report Distribution Vulnerability Enables Remote Takeover in Oracle PeopleSoft

Sun, 20 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Exploit in PeopleSoft Report Distribution Enables Full Compromise
Weaknesses CWE-285

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Exploit in PeopleSoft Report Distribution Enables Full Compromise
Weaknesses CWE-285

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:43.554Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83017

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:03.440Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:08.563

Modified: 2026-09-21T17:08:45.443

Link: CVE-2026-83017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:45:07Z

Weaknesses