Junglewise Threat Intelligence

CVE-2026-73955: Oracle PeopleSoft Enterprise PeopleTools cross-site scripting in Charting

CVE-2026-73955 · Severity: high · CVSS 7.3 · Published 2026-09-15

Executive brief

Oracle PeopleSoft Enterprise PeopleTools is a widely-used business application platform for managing human resources, finance, and supply chain operations. A vulnerability in the Charting component allows a low-privileged user to craft malicious requests that, when clicked by another user, can lead to unauthorized access, modification, or deletion of critical business data. This could expose sensitive employee or financial records.

Technical details

This is a stored or reflected cross-site scripting (XSS) vulnerability in the Charting component of PeopleSoft Enterprise PeopleTools (versions 8.61–8.63). The vulnerability is easily exploitable over the network via HTTP and requires low-level privileges and user interaction (a victim must click a malicious link). Successful exploitation grants an attacker the ability to read, modify, or delete critical data within PeopleSoft Enterprise PeopleTools. The vulnerability has a CVSS 3.1 score of 7.3 (high severity) with high confidentiality and integrity impacts. Patches are expected from Oracle as part of their regular security update cycle.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61–8.63

Timeline

  • 2026-09-15: disclosed: Public disclosure via NVD and Oracle security alert

References

Related threats