Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Affects Network Security
CVE-2026-73954

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-73954?

A significant security vulnerability exists in Oracle’s PeopleSoft Enterprise PeopleTools, specifically within the Business Interlink component. This issue affects supported versions 8.61 to 8.63, allowing an unauthenticated attacker with network access via HTTP to exploit the system. If successfully exploited, this vulnerability could lead to a complete compromise of PeopleSoft Enterprise PeopleTools, hindering the confidentiality, integrity, and availability of the affected systems. Organizations are urged to review their systems and apply necessary updates to mitigate potential risks.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.