Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise PeopleTools, specifically within the OpenSearch Dashboards component used for data visualization and analysis. An attacker could trick a legitimate user into performing an action that allows the attacker to gain unauthorized access to sensitive business data. This could result in the exposure of critical organizational information or a complete breach of all data accessible through the PeopleTools platform.
Technical details
A vulnerability in the OpenSearch Dashboards component of Oracle PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62) allows an unauthenticated remote attacker to compromise the system via HTTP. The vulnerability is characterized by a CVSS 3.1 scope change (S:C), indicating that a successful exploit can impact components beyond the immediate PeopleTools environment. While the attack is easily exploitable, it requires human interaction (UI:R) from a user other than the attacker. Successful exploitation results in a high impact on confidentiality (C:H), potentially leading to unauthorized access to all data accessible to the affected PeopleTools instance. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory