Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Affects Business Interlink Component
CVE-2026-82993

8.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-82993?

This vulnerability in Oracle's PeopleSoft Enterprise PeopleTools allows low privileged attackers to exploit its Business Interlink component with network access via HTTP. Affected versions 8.61 to 8.63 are particularly susceptible, potentially leading to unauthorized access and manipulation of critical data. Successful exploitation may result in attackers gaining complete access to protected data and the ability to make unauthorized updates or deletions, posing a serious risk to organizations relying on these systems.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.