CVE-2026-73960
moderateUnauthenticated Denial-of-Service in Oracle PeopleSoft PeopleTools 8.61-8.63 (Ren Server)
CVE-2026-73960 is an easily exploitable vulnerability in the Ren Server component of Oracle PeopleSoft Enterprise PeopleTools, affecting supported versions 8.61 through 8.63. An unauthenticated attacker with network access via HTTP can send crafted requests that cause the PeopleSoft application server environment to hang or crash repeatedly, resulting in a complete denial of service. The flaw impacts availability only (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), with no impact on confidentiality or integrity. Any organization exposing the PeopleSoft PeopleTools web tier over HTTP/HTTPS is affected. There is no known public proof of concept and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply Oracle's Critical Patch Update for PeopleTools as soon as it is available and move off the affected 8.61-8.63 releases. Restrict HTTP access to the PeopleSoft web tier (Ren Server/PIA) to trusted networks or VPN and place it behind a WAF or reverse proxy that can rate-limit unauthenticated traffic. Review web server and application logs for repeated unauthenticated requests or abnormal crash/hang patterns on the PIA tier.
| Oracle PeopleSoft Enterprise PeopleTools | 8.61-8.63 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.