CVE-2026-60873
Analyzed Analyzed - Analysis Complete

Privilege Escalation in Oracle PeopleSoft PeopleTools

Vulnerability report for CVE-2026-60873, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-21

Assigner: Oracle

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-21
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle peoplesoft_enterprise_peopletools From 8.61 (inc) to 8.63 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle PeopleSoft Enterprise PeopleTools (versions 8.61-8.63) within the Data Mover component. It allows a highly privileged attacker with local system access to potentially compromise the software. Exploitation requires human interaction from another user and could lead to unauthorized data access or modification, as well as partial denial of service.

Detection Guidance

Detection of CVE-2026-60873 requires monitoring PeopleSoft Enterprise PeopleTools for unauthorized data access or modification. Check logs for suspicious activity in Data Mover components, such as unusual user actions or privilege escalations. Review access logs for unexpected modifications to critical data files.

Impact Analysis

If exploited, this vulnerability could allow attackers to create, delete, or modify critical data within PeopleSoft Enterprise PeopleTools. It may also grant unauthorized access to sensitive data and cause partial system disruptions, impacting operations dependent on this software.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information security). Unauthorized data exposure or alteration risks regulatory penalties and loss of trust.

Mitigation Strategies

Apply the latest Oracle Critical Patch Update (CPU) for PeopleSoft Enterprise PeopleTools versions 8.61-8.63 to address the vulnerability. Ensure only trusted users have high privileged access to the infrastructure where PeopleSoft executes. Monitor for unauthorized data modifications or access patterns in PeopleSoft logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60873. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart