Executive brief
Oracle PeopleSoft Enterprise PT PeopleTools, a foundational platform for managing PeopleSoft applications, contains a vulnerability in its Application Server component. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. A successful attack could lead to a complete takeover of the application, potentially exposing sensitive business data and disrupting critical operations.
Technical details
This vulnerability is classified as a Missing Authentication for Critical Function (CWE-306) within the Application Server component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. An unauthenticated attacker can exploit this flaw via HTTP over a network. While the attack is characterized as having high complexity, a successful exploit allows for a complete compromise of the PeopleTools environment, impacting confidentiality, integrity, and availability. The vulnerability was disclosed in the June 2026 Oracle Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle and NVD publication.