Executive brief
Oracle PeopleSoft Enterprise PeopleTools is a critical middleware platform used to manage enterprise human resources, payroll, and finance operations. An unauthenticated, network-accessible vulnerability in the Ren Server component allows remote attackers to crash the service repeatedly, causing complete denial of service to dependent business processes and disrupting access to payroll, benefits, and HR systems.
Technical details
This vulnerability is a denial-of-service condition in the Ren Server component of PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw is easily exploitable and requires no authentication or user interaction; an attacker with network access can send a crafted HTTP request to trigger a hang or repeatable crash of the service. The vulnerability results in complete unavailability (DoS) of the affected system. Patches from Oracle are expected in the September 2026 security update cycle.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61 to 8.63
Timeline
- 2026-09-15: disclosed