Junglewise Threat Intelligence

CVE-2026-87264: Oracle PeopleSoft Enterprise PeopleTools data integrity violation in Integration Broker

CVE-2026-87264 · Severity: high · CVSS 7.7 · Published 2026-09-15

Executive brief

Oracle PeopleSoft Enterprise PeopleTools is a widely-used enterprise application platform for managing HR, finance, and business processes. This vulnerability in the Integration Broker component allows a low-privileged network attacker to create, delete, or modify critical business data across PeopleSoft and potentially connected systems without proper authorization. Successful exploitation could result in unauthorized changes to employee records, financial data, or other sensitive business information, with broader impact to integrated applications.

Technical details

This is an integrity violation vulnerability in the Integration Broker component of PeopleSoft Enterprise PeopleTools versions 8.61–8.63. The vulnerability is easily exploitable and requires only network access (HTTP) and low-level privileges, with no user interaction needed. An authenticated attacker can craft HTTP requests to create, delete, or modify critical data accessible through the Integration Broker, potentially affecting not only PeopleSoft but also downstream systems that consume PeopleTools data and services. The scope is marked as changed, indicating impacts extend beyond the vulnerable component. Patch status and detailed remediation guidance should be confirmed from Oracle's official security bulletin.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63

Timeline

  • 2026-09-15: disclosed

References

Related threats