Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Integrity
Action: Patch Now
AI Analysis

Impact

Vulnerability in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools, identified as CWE-284, allows a low-privileged attacker with network access via HTTP to create, delete, or modify critical data, thereby compromising data integrity and potentially enabling unauthorized creation, deletion, or alteration of all PeopleSoft accessible data.

Affected Systems

Affects Oracle PeopleSoft Enterprise PeopleTools, specifically the Integration Broker component, for versions 8.61 through 8.63.

Risk and Exploitability

The flaw can be exploited remotely using an HTTP connection; its CVSS 3.1 score of 7.7 indicates a high severity for data integrity. The EPSS score is below 1%, suggesting that exploitation is currently unlikely, and it is not listed in the CISA KEV catalog. Nevertheless, because the vulnerability is triggered through a web interface, administrators should restrict external access or apply the vendor patch promptly to mitigate the risk of integrity compromise.

Generated by OpenCVE AI on September 20, 2026 at 05:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch for PeopleSoft Enterprise PeopleTools as provided on the security alert page.
  • Restrict external network access to the Integration Broker interface using firewall rules or VPN, limiting traffic to trusted hosts.
  • Disable or remove the Integration Broker service if it is not required for business processes.
  • Monitor PeopleSoft logs for anomalous activity and enforce least‑privilege user policies.

Generated by OpenCVE AI on September 20, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via PeopleSoft Integration Broker
Weaknesses CWE-269

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via PeopleSoft Integration Broker
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:11:12.059Z

Reserved: 2026-09-08T21:49:12.407Z

Link: CVE-2026-87264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:15.040

Modified: 2026-09-17T16:18:21.380

Link: CVE-2026-87264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses