CVE-2026-83070
moderateAuthenticated Data Disclosure in Oracle PeopleSoft Interaction Hub 9.1
Oracle PeopleSoft Enterprise PRTL Interaction Hub 9.1 (Enterprise Portal component) contains an easily exploitable vulnerability that allows a low-privileged, authenticated attacker with network access via HTTP to compromise the Interaction Hub. Because the flaw changes scope (CVSS S:C), a successful attack can expose data beyond the Interaction Hub itself, potentially affecting other integrated PeopleSoft products. The impact is entirely on confidentiality: unauthorized access to critical data or complete access to all Interaction Hub-accessible data (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Organizations running the affected 9.1 release are exposed, particularly those with internet-facing portals. There is no known public proof-of-concept, no evidence of in-the-wild exploitation, and the CVE is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE for PeopleSoft Interaction Hub 9.1 as soon as it is available, as Oracle does not issue standalone patches outside the CPU schedule. Restrict Interaction Hub portals to VPN or trusted networks where possible, and review the privileges of low-privilege portal accounts since exploitation requires only an authenticated low-privilege session. Monitor access logs for anomalous data retrieval by ordinary portal users across integrated PeopleSoft applications.
| Oracle PeopleSoft Enterprise PRTL Interaction Hub (component: Enterprise Portal) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. While the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.