Junglewise Threat Intelligence

CVE-2026-60152: Oracle PeopleSoft Enterprise PeopleTools data manipulation in Panel Processor

CVE-2026-60152 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise PeopleTools, a suite used for managing enterprise applications, contains a security vulnerability in its Panel Processor component. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete certain business data. While the attacker does not need a password to launch the attack, they do require a victim to interact with a malicious link or page.

Technical details

A vulnerability in the Panel Processor component of Oracle PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62) allows for unauthorized data access and modification. The flaw is exploitable over the network via HTTP without authentication, though it requires human interaction (User Interaction: Required) from a legitimate user, suggesting a Cross-Site Scripting (XSS) or similar request forgery class of vulnerability. An attacker who successfully exploits this can gain unauthorized read access to a subset of data and perform unauthorized updates, inserts, or deletions. The impact is limited to confidentiality and integrity with no impact on availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.

References

Related threats