Vulnerability in Oracle PeopleSoft Tuxedo Component Affecting Multiple Versions
CVE-2026-60902

7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60902?

A security issue in Oracle's PeopleSoft Enterprise PeopleTools, specifically within the Tuxedo component, permits attackers with low privileges to exploit the system. This vulnerability targets versions 8.61 to 8.63, allowing unauthorized users who can log on to the relevant infrastructure to potentially assume control of the PeopleSoft environment. Exploitation could lead to significant breaches in confidentiality, integrity, and availability, making it crucial for organizations to address this issue promptly.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.