CVE-2026-83017
moderateLow-Privilege Takeover Flaw in Oracle PeopleSoft PeopleTools 8.61–8.63
CVE-2026-83017 is a high-severity vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 through 8.63. It is easily exploitable by a low-privileged, authenticated attacker with network access via HTTP, who can leverage the flaw to compromise the PeopleTools instance entirely. Successful attacks result in a full takeover of the application, with high impact on the confidentiality, integrity, and availability of PeopleSoft data (CVSS 3.1 base score 8.8). Any organization running an affected PeopleTools release and exposing the environment to users over the network is at risk, particularly if the portal is internet-facing or broadly accessible internally. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83017 to all PeopleTools 8.61–8.63 environments as a priority. Until patched, restrict network reachability of PeopleSoft portals (especially internet-facing instances), enforce least-privilege role assignments, and review Report Distribution activity and low-privileged account behavior for signs of misuse.
| Oracle PeopleSoft Enterprise PeopleTools | 8.61–8.63 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.