Junglewise Threat Intelligence

CVE-2026-83015: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in Cube Manager

CVE-2026-83015 · Severity: high · CVSS 7 · Published 2026-09-15

Executive brief

PeopleSoft Enterprise PeopleTools is an enterprise application platform used by organizations to manage core business processes and data. A local privilege escalation vulnerability in the Cube Manager component allows an authenticated user with low-level access to the system to gain full control over the PeopleTools infrastructure, potentially exposing sensitive business data and disrupting critical operations.

Technical details

This is a local privilege escalation vulnerability affecting the Cube Manager component of PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability requires local system access and a valid low-privileged logon credential; it is difficult to exploit due to high attack complexity. Successful exploitation allows an attacker to achieve complete compromise of the PeopleTools system with confidentiality, integrity, and availability impact. No information regarding a patch is currently available; Oracle has not released a fix as of the advisory publication date.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63

Timeline

  • 2026-09-15: disclosed

References

Related threats