ZeroHour

CVE-2026-83070

moderate

Authenticated Data Disclosure in Oracle PeopleSoft Interaction Hub 9.1

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

Oracle PeopleSoft Enterprise PRTL Interaction Hub 9.1 (Enterprise Portal component) contains an easily exploitable vulnerability that allows a low-privileged, authenticated attacker with network access via HTTP to compromise the Interaction Hub. Because the flaw changes scope (CVSS S:C), a successful attack can expose data beyond the Interaction Hub itself, potentially affecting other integrated PeopleSoft products. The impact is entirely on confidentiality: unauthorized access to critical data or complete access to all Interaction Hub-accessible data (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Organizations running the affected 9.1 release are exposed, particularly those with internet-facing portals. There is no known public proof-of-concept, no evidence of in-the-wild exploitation, and the CVE is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE for PeopleSoft Interaction Hub 9.1 as soon as it is available, as Oracle does not issue standalone patches outside the CPU schedule. Restrict Interaction Hub portals to VPN or trusted networks where possible, and review the privileges of low-privilege portal accounts since exploitation requires only an authenticated low-privilege session. Monitor access logs for anomalous data retrieval by ordinary portal users across integrated PeopleSoft applications.

Affected
Oracle PeopleSoft Enterprise PRTL Interaction Hub (component: Enterprise Portal)
Estimated exposure
moderate≈3,000-10,000 internet-exposed PeopleSoft portals (out of roughly 5,000-10,000 organizations running PeopleSoft) — Public internet scans (e.g., Shodan/Censys) historically show a few thousand PeopleSoft sign-in/portal pages reachable on the open web, and PeopleSoft is deployed at thousands of large enterprises, universities, and government agencies,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. While the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.