CVE-2026-60152: Medium severity Oracle PeopleSoft Enterprise PeopleTools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle PeopleSoft PeopleTools (Panel Processor)to a version that resolves this vulnerability.Fixed in 8.61 - Upgrade
Upgrade
Oracle PeopleSoft PeopleTools (Panel Processor)to a version that resolves this vulnerability.Fixed in 8.62
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60152?
The severity of CVE-2026-60152 is medium with a CVSS score of 5.4.
How do I fix CVE-2026-60152?
To fix CVE-2026-60152, update to the latest version of Oracle PeopleSoft Enterprise PeopleTools that is not affected by this vulnerability.
What impact does CVE-2026-60152 have on my system?
CVE-2026-60152 allows an unauthenticated attacker with network access to potentially compromise the PeopleSoft Enterprise system.
Which versions of Oracle PeopleSoft are affected by CVE-2026-60152?
The affected versions of Oracle PeopleSoft are 8.61 and 8.62.
Is CVE-2026-60152 easily exploitable?
Yes, CVE-2026-60152 is considered easily exploitable due to its requirement for only network access via HTTP.