CVE-2026-21961
BaseFortify
Publication date: 2026-01-20
Last updated on: 2026-01-29
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | peoplesoft_enterprise_hcm_human_resources | 9.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Oracle PeopleSoft Enterprise HCM Human Resources product, specifically in the Company Dir / Org Chart Viewer and Employee Snapshot components. It allows an unauthenticated attacker with network access via HTTP to exploit the system. The attack requires human interaction from someone other than the attacker. Successful exploitation can lead to unauthorized reading, updating, inserting, or deleting of some accessible data within PeopleSoft Enterprise HCM Human Resources.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing unauthorized access to sensitive data within PeopleSoft Enterprise HCM Human Resources. An attacker could read confidential information or modify data without permission, potentially leading to data integrity issues and exposure of sensitive employee information. This could disrupt business operations and compromise data security.