Remote Code Execution Vulnerability in Oracle PeopleSoft Enterprise PeopleTools nVision
CVE-2026-60967

8.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60967?

The vulnerability in Oracle PeopleSoft Enterprise PeopleTools nVision enables an unauthenticated attacker with network access to exploit the system. This flaw requires human interaction from a third party, which makes it a potential target for social engineering attacks. Successful exploitation can lead to a complete compromise of the PeopleSoft system, affecting confidentiality, integrity, and availability of the data within. Organizations utilizing versions 8.61 through 8.63 should take immediate precautions to mitigate risks associated with this vulnerability.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.