Executive brief
Oracle PeopleSoft Enterprise PeopleTools is a widely-used business application platform for managing human resources, finance, and supply chain operations. A vulnerability in the Charting component allows a low-privileged user to craft malicious requests that, when clicked by another user, can lead to unauthorized access, modification, or deletion of critical business data. This could expose sensitive employee or financial records.
Technical details
This is a stored or reflected cross-site scripting (XSS) vulnerability in the Charting component of PeopleSoft Enterprise PeopleTools (versions 8.61–8.63). The vulnerability is easily exploitable over the network via HTTP and requires low-level privileges and user interaction (a victim must click a malicious link). Successful exploitation grants an attacker the ability to read, modify, or delete critical data within PeopleSoft Enterprise PeopleTools. The vulnerability has a CVSS 3.1 score of 7.3 (high severity) with high confidentiality and integrity impacts. Patches are expected from Oracle as part of their regular security update cycle.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61–8.63
Timeline
- 2026-09-15: disclosed: Public disclosure via NVD and Oracle security alert