ZeroHour

CVE-2026-73954

moderate

Unauthenticated Takeover Flaw in Oracle PeopleSoft PeopleTools Business Interlink

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-73954 is a difficult-to-exploit vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 through 8.63. An unauthenticated attacker with network access via HTTP can trigger the flaw and compromise the PeopleTools installation, with successful attacks resulting in a complete takeover impacting confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack complexity (AC:H) means exploitation likely requires specialized conditions or race-like timing, which lowers the practical risk somewhat despite the severe impact. Affected organizations are enterprises and institutions running the affected PeopleTools versions, particularly those with PeopleSoft internet-facing HTTP endpoints. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.

What to do: Apply Oracle's Critical Patch Update remediation for this CVE and move to a patched PeopleTools release rather than remaining on 8.61–8.63. Restrict external HTTP access to PeopleSoft environments (VPN/IP allowlisting, reverse proxy, WAF rules) so Business Interlink endpoints are not internet-reachable. Review HTTP access logs on affected systems for unauthenticated anomalous requests and verify integrity of application servers if exposure was prolonged.

Affected
Oracle PeopleSoft Enterprise PeopleTools (Business Interlink component)8.61 - 8.63
Estimated exposure
moderate≈1,000–5,000 internet-exposed PeopleSoft instances, with a global installed base likely in the tens of thousands — PeopleSoft is on-premises enterprise software deployed mainly at large organizations, and public internet scan services typically show only a few thousand exposed PeopleSoft/PeopleTools endpoints at any time.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.