Low Privileged Access Vulnerability in Oracle PeopleSoft Integration Broker
CVE-2026-87264

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87264?

A vulnerability exists in the PeopleSoft Enterprise PeopleTools product by Oracle, specifically within the Integration Broker component. This security flaw permits a low privileged attacker with network access via HTTP to exploit the system. Though the vulnerability is localized within PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63, its impact can extend beyond, affecting additional products. Exploitation may enable unauthorized users to create, delete, or modify critical data accessible within PeopleSoft Enterprise PeopleTools, posing significant risks to data integrity and security.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61 <= 8.63

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.