Executive brief
PeopleSoft Enterprise PeopleTools is an application platform used by organizations to manage human resources and business processes. A difficult-to-exploit vulnerability in the Business Interlink component allows an unauthenticated attacker with network access to compromise the system and gain complete control over PeopleSoft deployments, potentially exposing sensitive employee and business data.
Technical details
The vulnerability is a difficult-to-exploit flaw in the Business Interlink component of PeopleSoft Enterprise PeopleTools versions 8.61–8.63. It can be exploited by an unauthenticated attacker with network access via HTTP to achieve remote compromise and complete system takeover. No user interaction is required. While the exact vulnerability class is not specified in the advisory, the high-impact outcome (full confidentiality, integrity, and availability compromise) and network-accessible attack vector suggest a serious authentication bypass, injection flaw, or deserialization vulnerability. Patches are expected from Oracle as part of their September 2026 security update cycle.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63
Timeline
- 2026-09-15: disclosed