Executive brief
A vulnerability exists in Oracle PeopleSoft Enterprise PeopleTools, a suite of tools used to build and customize PeopleSoft applications. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data. While the attack requires existing administrative credentials, a successful exploit could lead to a significant exposure of critical organizational information.
Technical details
An information disclosure vulnerability exists in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass confidentiality controls, resulting in unauthorized access to critical data or complete access to all data accessible through PeopleTools. The vulnerability has a CVSS 3.1 base score of 4.9, reflecting high confidentiality impact but requiring high privileges (PR:H) and having no impact on integrity or availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62
Timeline
- 2026-07-21: advisory: NVD published the CVE record based on Oracle's disclosure.