Data Manipulation Vulnerability in Oracle PeopleSoft Enterprise PeopleTools
CVE-2026-60873

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60873?

A vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle enables a high privileged attacker with logon access to the infrastructure where the software operates to compromise its functionality. Exploiting this vulnerability necessitates human interaction from someone other than the attacker, which complicates the exploitation process. Although the vulnerability is located within PeopleSoft Enterprise PeopleTools, it poses a risk of impacting associated products significantly. If successfully exploited, this vulnerability can lead to unauthorized creation, deletion, or modification of critical data, along with complete access to all data accessible through PeopleSoft. Additionally, it can result in partial denial of service for the service itself.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.