Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation leading to full control of PeopleSoft Enterprise PeopleTools
Action: Patch Now
AI Analysis

Impact

A vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged user who has logged into the underlying infrastructure to compromise the application. Successful exploitation PeopleTools and consequently exposes all data and services controlled by the system, affecting confidentiality, integrity and availability. The weakness permits the attacker to bypass normal security controls and gain full operational control of the application environment.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools in versions 8.61 through 8.63 are affected. The flaw resides in the SQR component of PeopleSoft.

Risk and Exploitability

The CVSS 3.1 base score is 7.8, indicating a high‑severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Attack requires the attacker to already have a logged‑on session on the infrastructure where PeopleSoft executes, implying a local attack vector and low complexity. to compromise the application.

Generated by OpenCVE AI on September 17, 2026 at 05:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for PeopleSoft Enterprise PeopleTools 8.61‑8.63 to fix the SQR component flaw
  • Re‑evaluate and reduce user privileges on the PeopleSoft platform to the minimum required roles, especially for accounts that can execute SQR scripts
  • Monitor PeopleSoft logs for unusual or unauthorized SQR execution and investigate promptly

Generated by OpenCVE AI on September 17, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in PeopleSoft Enterprise PeopleTools (SQR)

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:37.803Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83018

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:06.365Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:08.700

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses