Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Panel Processor
CVE-2026-60152

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60152?

A vulnerability exists in the Panel Processor component of Oracle PeopleSoft Enterprise PeopleTools that can be exploited by an unauthenticated attacker over HTTP. This flaw affects versions 8.61 and 8.62, enabling unauthorized users to execute operations that compromise the integrity and confidentiality of accessible data. Successful exploitation requires user interaction, increasing the risk of unauthorized updates, inserts, deletions, and potential data exposure. Organizations using the affected versions should assess their systems for potential risks and apply the necessary mitigations.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.