Executive brief
Oracle PeopleSoft Enterprise PeopleTools is a core platform used by organizations to manage human resources, payroll, and financial data. A vulnerability in the Business Interlink component allows a low-privileged user with network access to bypass authentication controls and gain unauthorized access to sensitive employee and financial data, or modify critical business information.
Technical details
This is an authentication or authorization bypass vulnerability in the Business Interlink component of PeopleSoft Enterprise PeopleTools. The flaw is network-reachable via HTTP and requires low privileges to exploit (such as a standard user account), with no user interaction required. An attacker can achieve unauthorized read access to sensitive data with high confidentiality impact, as well as limited unauthorized write access (insert, update, delete) affecting data integrity. The scope is marked as changed, indicating the vulnerability may enable attacks against other connected systems. Affected versions are 8.61 through 8.63; patches or guidance should be available from Oracle.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63
Timeline
- 2026-09-15: disclosed