Junglewise Threat Intelligence

CVE-2026-83014: Oracle PeopleSoft PeopleTools data modification and denial of service in Cube Manager

CVE-2026-83014 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

Oracle PeopleSoft PeopleTools is an enterprise application platform used to build and manage HR, finance, and supply chain systems. A vulnerability in the Cube Manager component allows a low-privilege attacker with network access to modify, delete, or create critical data, and to cause the application to crash or hang, disrupting business operations and potentially exposing sensitive employee or financial information.

Technical details

This vulnerability in the Cube Manager component of PeopleSoft PeopleTools is easily exploitable via network access (HTTP) and requires only low-privilege authentication. The vulnerability allows an attacker to perform unauthorized data manipulation (creation, deletion, modification) and denial-of-service attacks. The attack vector is network-based with low complexity and no user interaction required. Successful exploitation can result in both integrity violations (data modification) and availability impact (service disruption). Affected versions are PeopleTools 8.61 through 8.63; patch availability was expected from Oracle's security advisory published in September 2026.

Affected products

  • Oracle PeopleSoft PeopleTools 8.61-8.63

Timeline

  • 2026-09-15: disclosed

References

Related threats