Executive brief
Oracle PeopleSoft Enterprise PeopleTools is a widely used enterprise resource planning (ERP) and human capital management platform. A privilege escalation vulnerability in the Report Distribution component allows low-privileged users with network access to gain complete control over the system, risking theft of sensitive employee and financial data, unauthorized system modifications, and business continuity disruption.
Technical details
This vulnerability is an easily exploitable privilege escalation in the Report Distribution component of PeopleSoft Enterprise PeopleTools versions 8.61–8.63. The flaw allows a low-privileged attacker with network access via HTTP to escalate privileges and achieve full system compromise (confidentiality, integrity, and availability impact). No additional preconditions such as user interaction are required. The vulnerability has not been publicly exploited and affects the supported version range 8.61–8.63; patch availability status is not explicitly documented in the advisory.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63
Timeline
- 2026-09-15: disclosed