ZeroHour

CVE-2026-83018

moderate

Local Privilege Escalation via SQR in Oracle PeopleSoft PeopleTools 8.61-8.63

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83018 is a local privilege escalation flaw in the SQR reporting component of Oracle PeopleSoft Enterprise PeopleTools, affecting supported versions 8.61 through 8.63. A low-privileged attacker who already has logon access to the operating system or infrastructure where PeopleTools executes can trigger the flaw without user interaction to fully compromise the PeopleTools installation. Successful exploitation results in complete takeover of PeopleTools with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). The attack vector is local (AV:L), so remote unauthenticated exploitation is not possible; risk is concentrated inside organizations running affected versions. No public proof-of-concept exists and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses this SQR component flaw for PeopleTools 8.61-8.63, prioritizing hosts where multiple users or service accounts have local OS logon rights. Review local account inventory on PeopleSoft application and process scheduler servers and enforce least privilege to limit low-privileged footholds. Audit SQR-related logs and file activity on affected versions for signs of privilege escalation following patching.

Affected
Oracle PeopleSoft Enterprise PeopleTools8.61-8.63
Estimated exposure
moderateLikely a few thousand installations worldwide (subset of PeopleSoft's roughly 10,000+ customer base running PeopleTools 8.61-8.63) — PeopleSoft is enterprise ERP software deployed by an estimated 10,000+ organizations globally (per market-intelligence trackers), and only the subset on the recent PeopleTools 8.61-8.63 releases is affected; these are behind corporate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.