Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle
CVE-2026-60884

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60884?

A vulnerability exists in the Panel Processor component of Oracle's PeopleSoft Enterprise PeopleTools. It affects versions 8.61 to 8.63 and allows low-privileged attackers with network access via HTTP to compromise the system. Exploitation requires human interaction from an uninvolved third party. Although the vulnerability is specifically within PeopleTools, successful attacks can have broader implications, potentially impacting access to the data of other linked products. Successfully exploiting this vulnerability may enable unauthorized updates, deletions, and reading of sensitive data, posing significant risks to data integrity and confidentiality.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.