Impact
The vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged attacker who can reach the system via HTTP to execute code or otherwise compromise the entire PeopleSoft application. The flaw results in complete loss of confidentiality, integrity and availability and can be used to take over the PeopleSoft system entirely. This is a high‑severity flaw identified as CVE‑2026‑83017 with a CVSS 3.1 base score of 8.8.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools, specifically the Report Distribution component. Affected versions have been listed as 8.61 through 8.63. The flaw impacts installations of those versions that expose the Report Distribution endpoint over the network.
Risk and Exploitability
The CVSS score of 8.8 indicates a high overall risk. The EPSS score of <1% suggests that, as of the last assessment, exploitation likelihood is very low, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the attack vector is inferred to be over a public or enterprise network via HTTP, allowing an attacker with low privileges on the network to trigger the vulnerability. Because the impact includes full takeover of the PeopleSoft application, the potential damage is severe, especially for organizations with sensitive data or critical business processes.
OpenCVE Enrichment