Executive brief
A vulnerability exists in the Deployment Package component of Oracle PeopleSoft PeopleTools, which is the underlying technology platform for PeopleSoft applications. An attacker with basic access to the server infrastructure where the software is installed can exploit this flaw to take full control of the PeopleTools environment. This could lead to a total loss of confidentiality, integrity, and availability of the business data and services managed by the system.
Technical details
A vulnerability classified as Improper Privilege Management (CWE-269) exists in the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. The flaw is easily exploitable by an unauthenticated attacker who has local access to the underlying infrastructure (OS-level logon) where PeopleTools is executing. Successful exploitation allows the attacker to bypass security controls and achieve a complete takeover of the PeopleTools environment. The attack vector is local (AV:L) and requires no elevated privileges (PR:N) or user interaction (UI:N). Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date