Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise PeopleTools, the underlying technology platform for PeopleSoft applications. An attacker with low-level access could trick a legitimate user into performing actions that allow the attacker to view, modify, or delete certain business data. This could lead to unauthorized data changes or the exposure of sensitive information across the PeopleSoft environment.
Technical details
This vulnerability affects the Security component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. It is classified as a cross-site style vulnerability (indicated by the CVSS scope change and requirement for user interaction) that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation requires a person other than the attacker to perform a specific action (user interaction). An attacker can achieve unauthorized read, update, insert, or delete access to a subset of data accessible through PeopleTools. The vulnerability is notable for its 'Scope Change,' meaning an exploit can impact components or products beyond the immediate PeopleTools security module.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update.
- 2026-07-21: advisory: NVD published the CVE record.