ZeroHour

CVE-2026-82993

moderate

Authenticated Data-Access Flaw in Oracle PeopleSoft PeopleTools 8.61-8.63

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools allows a low-privileged authenticated attacker with HTTP network access to compromise PeopleTools, with a scope change meaning successful attacks may also significantly impact additional products beyond PeopleTools itself. Successful exploitation results in unauthorized access to critical data or complete access to all PeopleTools-accessible data, plus unauthorized update, insert, or delete access to some of that data; availability is not impacted. The flaw carries a CVSS 3.1 base score of 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N). Any organization running PeopleTools versions 8.61 through 8.63 is affected. There is no known public proof-of-concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-82993 and move PeopleTools off the affected 8.61-8.63 range to the patched release. Restrict HTTP access to the PeopleSoft Pure Internet Architecture portal (including Business Interlink endpoints) to VPN or IP allowlists so low-privileged remote users cannot reach it directly from the internet. Review audit and HTTP access logs for authenticated accounts performing unusual bulk data reads or unexpected update/insert/delete activity.

Affected
Oracle PeopleSoft Enterprise PeopleTools8.61-8.63 (Business Interlink component)
Estimated exposure
moderate≈ low thousands of internet-exposed PeopleSoft instances; plausibly 5,000-10,000 organizations worldwide run affected PeopleTools 8.61-8.63 — PeopleSoft is deployed by large enterprises, universities, and governments (typically thousands of organizations, mostly intranet-only), while public scan engines show on the order of a few thousand exposed PeopleSoft sign-on portals, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.