ZeroHour

CVE-2026-83015

moderate

Privilege Escalation to Full Takeover in Oracle PeopleSoft PeopleTools Cube Manager (8.61-8.63)

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83015 is a difficult-to-exploit local privilege escalation vulnerability in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools, affecting supported versions 8.61 through 8.63. It is triggered by a low-privileged attacker who already has logon access to the host or infrastructure where PeopleTools executes, and it requires no user interaction. A successful attack allows the attacker to fully compromise PeopleSoft Enterprise PeopleTools, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.0). Only organizations running PeopleTools 8.61-8.63 with accessible server or infrastructure accounts are exposed; remote unauthenticated exploitation is not possible per the vector (AV:L/AC:H/PR:L). The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation in the wild is unlikely at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw and move affected PeopleTools 8.61-8.63 environments to a fixed, supported release. Restrict and audit local OS and application accounts on PeopleSoft web, app, and batch servers to least privilege, since exploitation requires an existing low-privileged logon. Review authentication and privilege-escalation logs on hosts running Cube Manager for suspicious activity by low-privileged accounts.

Affected
Oracle PeopleSoft Enterprise PeopleTools8.61-8.63
Estimated exposure
moderateseveral thousand organizations / on the order of 10^3-10^4 PeopleTools deployments, but only a subset of hosts with local accounts are exploitable — PeopleSoft is deployed at thousands of large enterprises, universities, and government agencies worldwide with a few thousand internet-reachable self-service portals in public scans, but the local attack vector limits real exploitability…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.