Executive brief
A vulnerability in the Deployment Package component of Oracle PeopleSoft PeopleTools could allow a high-privileged user to take full control of the system. PeopleTools is the underlying technology platform for PeopleSoft applications, and a compromise here can impact the security and availability of all integrated business data and processes. An attacker must already have administrative access to the local infrastructure where the software is running to perform this attack.
Technical details
This vulnerability is classified as improper privilege management (CWE-269) within the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools. It is locally exploitable by an attacker with high privileges (PR:H) on the underlying infrastructure. The exploit is characterized by a scope change (S:C), meaning a successful attack can impact components beyond the immediate PeopleTools environment. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability, effectively allowing a full system takeover. Affected versions include 8.61 and 8.62.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory