cve-2026-60883
HIGH CVSS 7.2 opencve
Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Timeline
- Published
- 2026-08-18 21:16 UTC
- Last Modified
- 2026-08-21
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
mitre | ||
| 3.1 | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
opencve |
References
No references available.
Linked Vulnerabilities
{
"cve": "CVE-2026-60883",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "[8.61,8.63]"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "PeopleSoft Enterprise PeopleTools",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "peoplesoft_enterprise_peopletools",
"vendor": "oracle"
}
],
"created": "2026-08-18T23:45:16.695957+00:00",
"title": "PeopleSoft Enterprise PeopleTools PeopleCode Privilege Escalation via HTTP",
"updated": "2026-08-21T16:45:03.485258+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_peopletools"
]
},
"epss": {
"score": 0.00486
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T20:59:17.375000+00:00",
"description": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/60xxx/CVE-2026-60883.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-21T03:56:28.941000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_peopletools"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:16:46.303000+00:00",
"description": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-60883.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-21T13:10:45.207000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_peopletools"
],
"weaknesses": [
"CWE-284",
"CWE-306"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_peopletools"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_peopletools"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "beb82e53-2d4c-4141-b8fd-fd36919b66c4"
},
{
"created": "2026-08-19T00:00:00+00:00",
"data": [
{
"details": {
"new": "High Privilege Takeover via HTTP in Oracle PeopleSoft Enterprise PeopleTools",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-20",
"CWE-94"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "7f6fc6da-7c00-4393-a006-cf7049c7823a"
},
{
"created": "2026-08-20T18:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-284",
"CWE-306"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "fc14eac0-81c9-43e9-9dd5-15fa2de7aba5"
},
{
"created": "2026-08-21T14:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "High Privilege Takeover via HTTP in Oracle PeopleSoft Enterprise PeopleTools"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-20",
"CWE-94"
]
},
"type": "weaknesses"
}
],
"id": "811d8a1c-3498-41f0-b4fb-29956b2ccde8"
},
{
"created": "2026-08-21T17:00:00+00:00",
"data": [
{
"details": {
"new": "PeopleSoft Enterprise PeopleTools PeopleCode Privilege Escalation via HTTP",
"old": null
},
"type": "title"
}
],
"id": "96908932-42c2-45a7-aa7d-5aab3b528bc6"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T20:59:17.375000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00486
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "PeopleSoft Enterprise PeopleTools PeopleCode Privilege Escalation via HTTP",
"provider": "enrichment"
},
"updated": {
"data": "2026-08-21T16:45:03.485258+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$peoplesoft_enterprise_peopletools"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284",
"CWE-306"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-08-18T20:59:17.375000+00:00",
"description": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-08-20T17:55:14.463000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/60xxx/CVE-2026-60883.json",
"weaknesses": [
"CWE-284",
"CWE-306"
]
}
}