ZeroHour

CVE-2026-83019

moderate

Authenticated Data Theft and DoS in Oracle PeopleSoft PeopleTools SQR (CVSS 8.1)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools allows a low-privileged attacker with network access via HTTP to compromise PeopleTools, gaining unauthorized access to critical data (or all PeopleTools-accessible data) and the ability to hang or repeatedly crash the service for complete denial of service. Exploitation requires valid low-privilege credentials and no user interaction, so realistic attackers are malicious insiders, compromised accounts, or users on networks that can reach the PeopleSoft web tier. Confidentiality and availability are severely impacted, but integrity is not affected per the CVSS vector (C:H/I:N/A:H). Oracle has addressed the flaw in its Critical Patch Update for the affected PeopleTools 8.61-8.63 releases, and there is no known public proof of concept or confirmed in-the-wild exploitation. Organizations running affected versions, especially those with internet-facing PeopleSoft instances, are the primary exposure.

What to do: Apply Oracle's latest Critical Patch Update for PeopleTools to remediate the SQR flaw in versions 8.61-8.63, prioritizing any instances reachable from the internet or untrusted networks. Restrict HTTP access to the SQR component and PeopleSoft web tier to trusted networks or VPN, audit low-privilege accounts for anomalous activity, and monitor logs for unusual data access patterns or repeated crashes and hangs.

Affected
Oracle PeopleSoft Enterprise PeopleTools (component: SQR)8.61-8.63
Estimated exposure
moderatelow thousands of internet-reachable PeopleSoft environments; plausibly tens of thousands to ~100k end users across affected organizations — Public internet scan services historically show on the order of 1,000-3,000 internet-exposed PeopleSoft instances, and PeopleSoft is deployed at several thousand large enterprises, universities, and government agencies worldwide, only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.