ZeroHour

CVE-2026-83017

moderate

Low-Privilege Takeover Flaw in Oracle PeopleSoft PeopleTools 8.61–8.63

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83017 is a high-severity vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 through 8.63. It is easily exploitable by a low-privileged, authenticated attacker with network access via HTTP, who can leverage the flaw to compromise the PeopleTools instance entirely. Successful attacks result in a full takeover of the application, with high impact on the confidentiality, integrity, and availability of PeopleSoft data (CVSS 3.1 base score 8.8). Any organization running an affected PeopleTools release and exposing the environment to users over the network is at risk, particularly if the portal is internet-facing or broadly accessible internally. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83017 to all PeopleTools 8.61–8.63 environments as a priority. Until patched, restrict network reachability of PeopleSoft portals (especially internet-facing instances), enforce least-privilege role assignments, and review Report Distribution activity and low-privileged account behavior for signs of misuse.

Affected
Oracle PeopleSoft Enterprise PeopleTools8.61–8.63
Estimated exposure
moderate≈5,000–10,000 organizations running PeopleSoft, with likely low thousands of internet-exposed portals — PeopleSoft is enterprise ERP software deployed at thousands of large organizations, and public internet scans typically show only a low-thousands count of exposed PeopleSoft sign-in pages.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.