Junglewise Threat Intelligence

CVE-2026-83018: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in SQR

CVE-2026-83018 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

Oracle PeopleSoft Enterprise PeopleTools is a suite of enterprise resource planning and workforce management components used by organizations to manage human capital and business operations. A local privilege escalation vulnerability in the SQR component allows a low-privileged user with system access to gain complete control of the PeopleTools environment, compromising confidentiality, integrity, and availability of critical business data and processes.

Technical details

This is a local privilege escalation vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools affecting versions 8.61 through 8.63. The vulnerability is easily exploitable and requires only local logon access to the infrastructure where PeopleTools executes, with low privilege level. Successful exploitation allows an attacker to achieve complete takeover of the PeopleTools environment with high impact across confidentiality, integrity, and availability. No active exploitation in the wild has been reported at the time of disclosure. Patches should be obtained from Oracle for affected versions.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61–8.63

Timeline

  • 2026-09-15: disclosed

References

Related threats