Executive brief
PeopleSoft Enterprise PeopleTools is an enterprise application platform used by organizations to manage core business processes and data. A local privilege escalation vulnerability in the Cube Manager component allows an authenticated user with low-level access to the system to gain full control over the PeopleTools infrastructure, potentially exposing sensitive business data and disrupting critical operations.
Technical details
This is a local privilege escalation vulnerability affecting the Cube Manager component of PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability requires local system access and a valid low-privileged logon credential; it is difficult to exploit due to high attack complexity. Successful exploitation allows an attacker to achieve complete compromise of the PeopleTools system with confidentiality, integrity, and availability impact. No information regarding a patch is currently available; Oracle has not released a fix as of the advisory publication date.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63
Timeline
- 2026-09-15: disclosed