CVE-2026-83018
moderateLocal Privilege Escalation via SQR in Oracle PeopleSoft PeopleTools 8.61-8.63
CVE-2026-83018 is a local privilege escalation flaw in the SQR reporting component of Oracle PeopleSoft Enterprise PeopleTools, affecting supported versions 8.61 through 8.63. A low-privileged attacker who already has logon access to the operating system or infrastructure where PeopleTools executes can trigger the flaw without user interaction to fully compromise the PeopleTools installation. Successful exploitation results in complete takeover of PeopleTools with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). The attack vector is local (AV:L), so remote unauthenticated exploitation is not possible; risk is concentrated inside organizations running affected versions. No public proof-of-concept exists and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update that addresses this SQR component flaw for PeopleTools 8.61-8.63, prioritizing hosts where multiple users or service accounts have local OS logon rights. Review local account inventory on PeopleSoft application and process scheduler servers and enforce least privilege to limit low-privileged footholds. Audit SQR-related logs and file activity on affected versions for signs of privilege escalation following patching.
| Oracle PeopleSoft Enterprise PeopleTools | 8.61-8.63 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.