Technology · Oracle
Oracle PeopleSoft Enterprise PeopleTools vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in Oracle PeopleSoft Enterprise PeopleTools: 0 in the last 7 days and 19 in the last 90 days, 2 of them critical and 2 exploited in the wild. The most recent, CVE-2026-87264, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 2
- Exploited in the wild
- 2
About Oracle PeopleSoft Enterprise PeopleTools
A software development framework used to build and customize Oracle PeopleSoft applications.
Latest Oracle PeopleSoft Enterprise PeopleTools vulnerabilities
- CVE-2026-87264: Oracle PeopleSoft Enterprise PeopleTools data integrity violation in Integration BrokerhighCVSS 7.7EPSS 0.3%
- CVE-2026-83019: Oracle PeopleSoft Enterprise PeopleTools unauthorized access and denial of service in SQRhighCVSS 8.1EPSS 0.4%
- CVE-2026-83018: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in SQRhighCVSS 7.8EPSS 0.2%
- CVE-2026-83017: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in Report DistributionhighCVSS 8.8EPSS 0.4%
- CVE-2026-83016: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in SQRhighCVSS 7.2EPSS 0.1%
- CVE-2026-83015: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in Cube ManagerhighCVSS 7EPSS 0.1%
- CVE-2026-83014: Oracle PeopleSoft PeopleTools data modification and denial of service in Cube ManagerhighCVSS 8.1EPSS 0.4%
- CVE-2026-82993: Oracle PeopleSoft Enterprise PeopleTools authentication bypass in Business InterlinkhighCVSS 8.5EPSS 0.3%
- CVE-2026-73960: Oracle PeopleSoft Enterprise PeopleTools denial of service in Ren ServerhighCVSS 7.5EPSS 0.5%
- CVE-2026-73955: Oracle PeopleSoft Enterprise PeopleTools cross-site scripting in ChartinghighCVSS 7.3EPSS 0.3%
- CVE-2026-73954: Oracle PeopleSoft Enterprise PeopleTools remote compromise in Business InterlinkhighCVSS 8.1EPSS 0.4%
- CVE-2026-60152: Oracle PeopleSoft Enterprise PeopleTools data manipulation in Panel ProcessormediumCVSS 5.4
- CVE-2026-47051: Oracle PeopleSoft Enterprise PeopleTools security bypass in Security componentmediumCVSS 5.4
- CVE-2026-47049: Oracle PeopleSoft PeopleTools information disclosure in PIA Core TechnologymediumCVSS 4.9
- CVE-2026-47048: Oracle PeopleSoft Enterprise PeopleTools security bypass in Security componentmediumCVSS 5.4
- CVE-2026-47026: Oracle PeopleSoft Enterprise PeopleTools data exposure in OpenSearch DashboardshighCVSS 7.4
- CVE-2026-47024: Oracle PeopleSoft Enterprise PeopleTools data manipulation in Panel ProcessormediumCVSS 5.4
- CVE-2026-47017: Oracle PeopleSoft Enterprise PeopleTools vulnerability in Process SchedulerhighCVSS 8.7
- CVE-2026-47015: Oracle PeopleSoft PeopleTools vulnerability in PIA Core TechnologyhighCVSS 7.1
- CVE-2026-35273: Oracle PeopleSoft PeopleTools compromise in Updates Environment Managementcriticalexploited in the wildCVSS 9.8EPSS 0.0%
- CVE-2019-2725: Oracle WebLogic Server, Injectioncriticalexploited in the wildCVSS 9.8
- CVE-2017-3300: Oracle PeopleSoft PeopleTools XSS in Multichannel FrameworkmediumCVSS 6.1
- CVE-2017-3299: Oracle PeopleSoft PeopleTools cross-site vulnerability in PIA Search FunctionalitymediumCVSS 6.1
- CVE-2017-3298: Oracle PeopleSoft Enterprise PeopleTools data manipulation in PIA Core TechnologymediumCVSS 6.1
- CVE-2017-3292: Oracle PeopleSoft PeopleTools Information Disclosure in Integration BrokermediumCVSS 5.7
Most severe Oracle PeopleSoft Enterprise PeopleTools vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-35273: Oracle PeopleSoft PeopleTools compromise in Updates Environment Managementcriticalexploited in the wildCVSS 9.8EPSS 0.0%
- CVE-2019-2725: Oracle WebLogic Server, Injectioncriticalexploited in the wildCVSS 9.8
- CVE-2026-83017: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in Report DistributionhighCVSS 8.8EPSS 0.4%
- CVE-2026-47017: Oracle PeopleSoft Enterprise PeopleTools vulnerability in Process SchedulerhighCVSS 8.7
- CVE-2026-82993: Oracle PeopleSoft Enterprise PeopleTools authentication bypass in Business InterlinkhighCVSS 8.5EPSS 0.3%
- CVE-2026-83019: Oracle PeopleSoft Enterprise PeopleTools unauthorized access and denial of service in SQRhighCVSS 8.1EPSS 0.4%
- CVE-2026-83014: Oracle PeopleSoft PeopleTools data modification and denial of service in Cube ManagerhighCVSS 8.1EPSS 0.4%
- CVE-2026-73954: Oracle PeopleSoft Enterprise PeopleTools remote compromise in Business InterlinkhighCVSS 8.1EPSS 0.4%
- CVE-2026-83018: Oracle PeopleSoft Enterprise PeopleTools privilege escalation in SQRhighCVSS 7.8EPSS 0.2%
- CVE-2026-87264: Oracle PeopleSoft Enterprise PeopleTools data integrity violation in Integration BrokerhighCVSS 7.7EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 8 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 11 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/peopletools.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle PeopleSoft Enterprise PeopleTools vulnerabilities", https://junglewise.ai/threats/technologies/peopletools, 26 September 2026.