CVE-2026-73954
moderateUnauthenticated Takeover Flaw in Oracle PeopleSoft PeopleTools Business Interlink
CVE-2026-73954 is a difficult-to-exploit vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 through 8.63. An unauthenticated attacker with network access via HTTP can trigger the flaw and compromise the PeopleTools installation, with successful attacks resulting in a complete takeover impacting confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack complexity (AC:H) means exploitation likely requires specialized conditions or race-like timing, which lowers the practical risk somewhat despite the severe impact. Affected organizations are enterprises and institutions running the affected PeopleTools versions, particularly those with PeopleSoft internet-facing HTTP endpoints. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply Oracle's Critical Patch Update remediation for this CVE and move to a patched PeopleTools release rather than remaining on 8.61–8.63. Restrict external HTTP access to PeopleSoft environments (VPN/IP allowlisting, reverse proxy, WAF rules) so Business Interlink endpoints are not internet-reachable. Review HTTP access logs on affected systems for unauthenticated anomalous requests and verify integrity of application servers if exposure was prolonged.
| Oracle PeopleSoft Enterprise PeopleTools (Business Interlink component) | 8.61 - 8.63 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.