Executive brief
A vulnerability exists in the Deployment Package component of Oracle PeopleSoft PeopleTools, a platform used for managing and deploying enterprise applications. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive business data. This could lead to the theft of critical information or the unauthorized modification and deletion of records within the system.
Technical details
This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools. It is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to achieve high confidentiality impact, potentially accessing all data within the component, and low integrity impact, allowing for unauthorized updates, insertions, or deletions of some data. The vulnerability affects versions 8.61 and 8.62. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date