Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote or privileged data access and denial of service
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the PeopleSoft Enterprise PeopleTools component SQR and allows a low-privileged, networked attacker to execute commands via HTTP. The vulnerability can lead to unauthorized access to all data that the web application can reach and can also trigger a complete denial of service by causing the application to hang or crash repeatedly. It is represented by CVSS 3.1 base score 8.1 with high impact to confidentiality and availability.

Affected Systems

Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. These are the systems that contain the vulnerable SQR component.

Risk and Exploitability

The attack vector is inferred to be external over HTTP, requiring only low privileges but network access. The EPSS score of less than 1 % indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, its high CVSS score and the possibility of full data exfiltration or service disruption mean that an organization using this product should consider the risk high if not mitigated.

Generated by OpenCVE AI on September 20, 2026 at 11:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a supported non‑affected version as described in the official advisory.
  • Configure the firewall to block all HTTP traffic to the PeopleSoft application from untrusted networks, allowing only whitelisted IP ranges.
  • Enable detailed logging of SQR execution and set alerts for unexpected crashes or hangs so that anomalous activity can be detected early.

Generated by OpenCVE AI on September 20, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Denial of Service via Low-Privilege HTTP in PeopleSoft SQR

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:32.347Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83019

cve-icon Vulnrichment

Updated: 2026-09-16T15:54:54.082Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:08.837

Modified: 2026-09-21T16:59:46.180

Link: CVE-2026-83019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:15:17Z

Weaknesses