Executive brief
A vulnerability exists in the Performance Monitor component of Oracle PeopleSoft PeopleTools, a platform used to manage and run PeopleSoft applications. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. A successful attack could lead to a complete takeover of the application, potentially exposing sensitive business data and disrupting operations.
Technical details
This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools. It affects versions 8.61 and 8.62. An unauthenticated attacker can exploit this over the network via HTTP, though the exploit is characterized as having high complexity. Successful exploitation allows for a complete compromise of the PeopleTools environment, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory