Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution leading to takeover
Action: Immediate patch
AI Analysis

Impact

The vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged attacker who can reach the system over HTTP to execute code or otherwise compromise the entire PeopleSoft application. The flaw results in complete loss of confidentiality, integrity and availability and can be used to take over the PeopleSoft system entirely. This is a high‑severity flaw identified as CVE‑2026‑83017 with a CVSS 3.1 base score of 8.8.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools, specifically the Report Distribution component. Affected versions are 8.61 through 8.63. The flaw impacts all installations running those versions and any environment that exposes the Report Distribution endpoint over the network.

Risk and Exploitability

The CVSS score of 8.8 indicates a high overall risk. The EPSS score of <1% suggests that, as of the last assessment, exploitation likelihood is very low, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the attack vector is inferred to be over a public or enterprise network via HTTP, allowing an attacker with low privileges on the network to trigger the vulnerability. Because the impact includes full takeover of the PeopleSoft application, the potential damage is severe, especially for organizations with sensitive data or critical business processes.

Generated by OpenCVE AI on September 17, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a version that removes the flaw (e.g., PeopleSoft 8.64 or newer).
  • If a patch is not yet available, block external HTTP access to the Report Distribution endpoint using firewall rules or network access control to limit connections to trusted hosts only.
  • Temporarily disable the Report Distribution feature in the PeopleSoft configuration until a patch is applied to reduce the attack surface.

Generated by OpenCVE AI on September 17, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Exploit in PeopleSoft Report Distribution Enables Full Compromise
Weaknesses CWE-285

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:43.554Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83017

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:03.440Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:08.563

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:30:08Z

Weaknesses