Executive brief
A vulnerability exists in the Deployment Package component of Oracle PeopleSoft PeopleTools, which is the underlying technology platform for PeopleSoft applications. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. A successful attack could lead to a complete takeover of the environment, potentially exposing sensitive business data and disrupting critical operations.
Technical details
This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools. It affects versions 8.61 and 8.62. An unauthenticated attacker can exploit this over HTTPS, though the attack is characterized as having high complexity. Successful exploitation allows for a complete takeover of the PeopleTools environment, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory