CVE-2026-83019

peoplesoft_enterprise_peopletools: Improper Access Control (CVE-2026-83019)

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

oraclepeoplesoft_enterprise_peopletools
8.61 – 8.63

Metrics

8.1
Source: nvd-v3
34.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-15 20:02 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-21 16:59 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:* versions from (including) 8.61 up to (including) 8.63
    • Reference Type: Oracle: https://www.oracle.com/security-alerts/cspusep2026.html Types: Vendor Advisory
  2. CVE Modified2026-09-16 17:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CWE: CWE-284
    • SSVC: {"id":"CVE-2026-83019","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-15 20:18 UTC· secalert_us@oracle.com
    • Description: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/83xxx/CVE-2026-83019.json">CVE-2026-83019</a>
    • Reference: https://www.oracle.com/security-alerts/cspusep2026.html