Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Product Charting by Oracle
CVE-2026-73955

7.3HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-73955?

A vulnerability exists in the Charting component of Oracle's PeopleSoft Enterprise PeopleTools, versions 8.61 to 8.63. This flaw allows low-privileged attackers with network access via HTTP to potentially compromise the PeopleSoft environment. While successful exploitation requires human interaction from a non-attacker, the consequences can be severe, leading to unauthorized creation, deletion, or modification of sensitive data. Attackers may gain access to critical data, affecting the integrity and confidentiality of all information managed by PeopleSoft Enterprise PeopleTools.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.