Junglewise Threat Intelligence

CVE-2026-83070: Oracle PeopleSoft Enterprise PRTL Interaction Hub unauthorized data access

CVE-2026-83070 · Severity: high · CVSS 7.7 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise PRTL Interaction Hub is a portal component used by organizations to manage employee interactions and access enterprise data. A vulnerability in this product allows a low-privileged network attacker to bypass authorization controls and read sensitive business data, potentially exposing employee records, payroll information, and other confidential content stored in the system.

Technical details

This is an authorization bypass or authentication weakness in the Enterprise Portal component of PeopleSoft Enterprise PRTL Interaction Hub version 9.1. The vulnerability is exploitable over HTTP by an attacker with low-privilege network access and requires no user interaction. An authenticated but low-privileged attacker can gain unauthorized access to critical data beyond their intended permissions. The scope changes (impacts additional products), suggesting the compromise may cascade to dependent systems. No patch status is publicly available; organizations should monitor Oracle security advisories for fixes.

Affected products

  • Oracle PeopleSoft Enterprise PRTL Interaction Hub 9.1

Timeline

  • 2026-09-15: disclosed

References