Impact
The vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged attacker who can reach the system over HTTP to execute code or otherwise compromise the entire PeopleSoft application. The flaw results in complete loss of confidentiality, integrity and availability and can be used to take over the PeopleSoft system entirely. This is a high‑severity flaw identified as CVE‑2026‑83017 with a CVSS 3.1 base score of 8.8.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools, specifically the Report Distribution component. Affected versions are 8.61 through 8.63. The flaw impacts all installations running those versions and any environment that exposes the Report Distribution endpoint over the network.
Risk and Exploitability
The CVSS score of 8.8 indicates a high overall risk. The EPSS score of <1% suggests that, as of the last assessment, exploitation likelihood is very low, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the attack vector is inferred to be over a public or enterprise network via HTTP, allowing an attacker with low privileges on the network to trigger the vulnerability. Because the impact includes full takeover of the PeopleSoft application, the potential damage is severe, especially for organizations with sensitive data or critical business processes.
OpenCVE Enrichment