Oracle PeopleSoft Vulnerability in PeopleTools SQR Component
CVE-2026-83018

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83018?

A security flaw exists in the SQR component of Oracle PeopleSoft Enterprise PeopleTools, where an attacker with low privileges can log in to the system and exploit this vulnerability. This significantly jeopardizes the integrity and confidentiality of the system, allowing unauthorized takeover of the PeopleTools environment. Organizations utilizing affected versions 8.61 to 8.63 should assess their security measures and apply necessary updates as recommended by Oracle to mitigate potential threats and secure their enterprise applications.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.