CVE-2026-60831: High severity Oracle PeopleSoft Enterprise PeopleTools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Oracle PeopleSoft Enterprise PeopleTools installations using the Integration Broker component on supported versions 8.61 through 8.63 are affected when reachable over HTTP from an attacker’s network location.
Does exploitation require authentication or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker with network access via HTTP, and it does not require user interaction. Exploitation is rated difficult, reflected by the high attack-complexity requirement.
What could a successful attacker achieve?
A successful attack can result in takeover of PeopleSoft Enterprise PeopleTools, with high impacts to confidentiality, integrity, and availability.