CVE-2026-60902: High severity Oracle PeopleSoft Enterprise PeopleTools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle PeopleSoft Enterprise PeopleTools (Tuxedo component)to a version that resolves this vulnerability.Fixed in 8.61-8.63
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Organizations running Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. Exploitation requires access to the infrastructure where PeopleTools executes, so exposure is limited to attackers who can log on to that environment with low privileges.
What level of access does an attacker need?
An attacker needs a low-privileged logon to the infrastructure hosting PeopleSoft Enterprise PeopleTools. No user interaction is required, but exploitation is described as difficult.
What could a successful attack achieve?
A successful attack can result in takeover of PeopleSoft Enterprise PeopleTools. Confidentiality, integrity, and availability can all be impacted.