Description
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. While the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft, specifically in version 9.1. The flaw allows a low‑privileged attacker with network access over HTTP to gain unauthorized access to the hub. This can result in disclosure of critical data or complete access to all data exposed by the hub. The weakness is a privilege escalation that can affect the confidentiality of the data while not impacting integrity or availability directly.

Affected Systems

Affected systems are Oracle PeopleSoft Enterprise PRTL Interaction Hub running version 9.1. The advisory notes that a scope change could allow attacks to impact additional related products that connect to the hub.

Risk and Exploitability

The CVSS score of 7.7 indicates a high‑severity vulnerability that requires network access and low attacker effort. The EPSS score is less than 1%, suggesting that widespread exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit operates over HTTP, it is likely to be discovered during routine web‑port scanning, making it a readily available attack vector for low‑privileged adversaries.

Generated by OpenCVE AI on September 17, 2026 at 04:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or upgrade to the latest Oracle PeopleSoft Enterprise PRTL Interaction Hub version as detailed in the official Oracle security advisory.
  • Restrict HTTP access to the Interaction Hub by limiting traffic to trusted networks or IP ranges and disabling or removing guest or default accounts.
  • Enable detailed logging for authentication and session activity, and monitor for anomalous access attempts to the hub.

Generated by OpenCVE AI on September 17, 2026 at 04:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Vulnerability in Oracle PeopleSoft PRTL Interaction Hub

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. While the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Prtl Interaction Hub
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_prtl_interaction_hub:9.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Prtl Interaction Hub
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Prtl Interaction Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:18.721Z

Reserved: 2026-08-31T15:40:57.337Z

Link: CVE-2026-83070

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:44.056Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:15.890

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses