PeopleTools Vulnerability in Oracle's PeopleSoft Enterprise Software
CVE-2026-60883
7.2HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-60883?
An access control vulnerability in Oracle’s PeopleSoft Enterprise PeopleTools component could allow an attacker with high privileges and network access to compromise the system via HTTP. Exploiting this vulnerability can lead to a complete takeover of the PeopleSoft Enterprise system, affecting the confidentiality, integrity, and availability of the data and services it provides. Organizations are advised to review their PeopleSoft installations and apply necessary updates to mitigate this risk.
Affected Version(s)
PeopleSoft Enterprise PeopleTools 8.61 <= 8.63