CVE-2026-83015

peoplesoft_enterprise_peopletools: Improper Access Control (CVE-2026-83015)

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

oraclepeoplesoft_enterprise_peopletools
8.61 – 8.63

Metrics

7.0
Source: nvd-v3
2.3 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-15 20:02 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-21 17:09 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:* versions from (including) 8.61 up to (including) 8.63
    • Reference Type: Oracle: https://www.oracle.com/security-alerts/cspusep2026.html Types: Vendor Advisory
  2. CVE Modified2026-09-16 17:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CWE: CWE-284
    • SSVC: {"id":"CVE-2026-83015","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-15 20:18 UTC· secalert_us@oracle.com
    • Description: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
    • CVSS V3.1: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/83xxx/CVE-2026-83015.json">CVE-2026-83015</a>
    • Reference: https://www.oracle.com/security-alerts/cspusep2026.html