CVE-2026-60883: High severity Oracle PeopleSoft Enterprise PeopleTools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs high-level privileges in PeopleSoft Enterprise PeopleTools and network access to the affected system over HTTP. No user interaction is required.
Which deployments are affected?
Affected supported versions are PeopleTools 8.61 through 8.63. The provided information does not state whether any particular default configuration changes exposure.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of PeopleSoft Enterprise PeopleTools, with high impact to confidentiality, integrity, and availability.