CVE-2026-60879: High severity Oracle PeopleSoft Enterprise PeopleTools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-level privileges and network access to the affected PeopleSoft Enterprise PeopleTools environment through SQL. No user interaction is required.
Which deployments are affected?
The affected component is Configuration Manager in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63.
What is the potential impact of successful exploitation?
Successful exploitation can lead to takeover of PeopleSoft Enterprise PeopleTools, with high impacts to confidentiality, integrity, and availability.