CVE-2026-83016
moderatePrivileged Local Takeover via SQR in Oracle PeopleSoft PeopleTools 8.61–8.63
CVE-2026-83016 is a difficult-to-exploit flaw in the SQR (Structured Query Reporter) component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 through 8.63. Exploitation requires an attacker who already holds high privileges and local logon access to the infrastructure running PeopleTools, plus interaction from a second person (e.g., tricking another user into opening or processing a malicious SQR report or file). A successful attack results in full takeover of PeopleTools, and because of a scope change, it may also significantly impact additional products beyond PeopleTools itself. The CVSS 3.1 base score is 7.2 (high), driven by high confidentiality, integrity, and availability impacts despite the demanding prerequisites. No public proof of concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and there is no indication of in-the-wild exploitation; a fix is delivered through Oracle's Critical Patch Update.
What to do: Apply the Oracle Critical Patch Update that addresses this CVE and verify you are on a patched PeopleTools release if currently on 8.61–8.63. Restrict local OS and administrator access on PeopleSoft servers to a minimal set of trusted accounts, since exploitation requires high-privilege local logon plus a victim's interaction. Review SQR report sources and job submission logs for unexpected or user-supplied report files, and remind administrators not to process untrusted SQR content.
| Oracle PeopleSoft Enterprise PeopleTools (component: SQR) | 8.61-8.63 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.