Executive brief
Oracle PeopleSoft PeopleTools is an enterprise application platform used to build and manage HR, finance, and supply chain systems. A vulnerability in the Cube Manager component allows a low-privilege attacker with network access to modify, delete, or create critical data, and to cause the application to crash or hang, disrupting business operations and potentially exposing sensitive employee or financial information.
Technical details
This vulnerability in the Cube Manager component of PeopleSoft PeopleTools is easily exploitable via network access (HTTP) and requires only low-privilege authentication. The vulnerability allows an attacker to perform unauthorized data manipulation (creation, deletion, modification) and denial-of-service attacks. The attack vector is network-based with low complexity and no user interaction required. Successful exploitation can result in both integrity violations (data modification) and availability impact (service disruption). Affected versions are PeopleTools 8.61 through 8.63; patch availability was expected from Oracle's security advisory published in September 2026.
Affected products
- Oracle PeopleSoft PeopleTools 8.61-8.63
Timeline
- 2026-09-15: disclosed