Executive brief
A security vulnerability exists in the Process Scheduler component of Oracle PeopleSoft Enterprise PeopleTools. This component manages background tasks and system processes. An attacker with low-level access could trick another user into performing an action that allows the attacker to view, modify, or delete sensitive business data across the entire system.
Technical details
This vulnerability affects the Process Scheduler component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. It is classified as a high-severity issue with a CVSS 3.1 base score of 8.7. The attack vector is network-based (HTTP), requiring low privileges and user interaction (UI:R). The vulnerability involves a scope change (S:C), meaning an exploit can impact components beyond the Process Scheduler itself. Successful exploitation grants the attacker high confidentiality and integrity impacts, potentially allowing for the unauthorized creation, deletion, or modification of all data accessible to PeopleTools. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory