CVE-2026-83015
peoplesoft_enterprise_peopletools: Improper Access Control (CVE-2026-83015)
Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
8.61 – 8.63Metrics
Show all metrics
Weakness classes (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-21 17:09 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:* versions from (including) 8.61 up to (including) 8.63
- Reference Type: Oracle: https://www.oracle.com/security-alerts/cspusep2026.html Types: Vendor Advisory
- CVE Modified2026-09-16 17:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE: CWE-284
- SSVC: {"id":"CVE-2026-83015","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-15 20:18 UTC· secalert_us@oracle.com
- Description: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- CVSS V3.1: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/83xxx/CVE-2026-83015.json">CVE-2026-83015</a>
- Reference: https://www.oracle.com/security-alerts/cspusep2026.html