ZeroHour

CVE-2026-83014

moderate

Privilege Abuse Flaw in Oracle PeopleSoft PeopleTools Cube Manager Enables Data Tampering and DoS

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83014 is an easily exploitable authorization weakness in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools, affecting supported releases 8.61 through 8.63. A remote attacker who already holds a low-privileged account and has HTTP access to the PeopleSoft application can exploit it to gain unauthorized ability to create, delete, or modify critical data (or all data the PeopleTools installation can reach) and to cause a hang or frequently repeatable crash, resulting in complete denial of service. The flaw has no confidentiality impact — it is an integrity and availability attack, reflected in the CVSS 3.1 base score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). Any organization running PeopleTools 8.61, 8.62, or 8.63 is affected, particularly those with broadly reachable web portals or large internal user bases where a low-privilege account is easy to obtain. There is no known public proof of concept and no indication of in-the-wild exploitation to date, but Oracle addresses it via its Critical Patch Update program.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all PeopleTools 8.61-8.63 environments — do not wait for a version upgrade, since Oracle patches these releases in place. Restrict HTTP access to PeopleSoft portals via VPN or network segmentation, audit and minimize low-privilege account grants, and review Cube Manager activity logs for unexpected data changes or crash patterns.

Affected
Oracle PeopleSoft Enterprise PeopleTools8.61, 8.62, 8.63
Estimated exposure
moderate≈5,000-10,000 organizations (a few thousand internet-reachable PeopleSoft portals) — PeopleSoft is on-premises enterprise software with a customer base commonly estimated in the low thousands of organizations, and public internet scans typically show only a few thousand exposed PeopleSoft sign-in pages; the requirement for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.