NCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise
Oracle has resolved multiple vulnerabilities in Oracle PeopleSoft Enterprise PeopleTools, including the modules Integration Broker, Data Mover, Configuration Manager, FIN Common Objects, FIN Lease Administration and CC Common Application Objects, specifically in versions 8.61 through 8.63 and 9.1 through 9.2. The vulnerabilities in Oracle PeopleSoft Enterprise PeopleTools and related modules allow an attacker via network access, often via HTTP or Oracle Net, without authentication or with low privileges, to completely take over the system or create, modify or delete critical data. Some vulnerabilities require user interaction, others do not. The impact concerns the confidentiality, integrity and availability of the system and data. The vulnerabilities include, among others, authentication bypass, privilege escalation, and execution of unauthorized actions. Specific components such as Integration Broker and Configuration Manager are also affected. The CVSS 3.1 base scores range from 4.4 to 9.8, with multiple vulnerabilities having a high score indicating significant security impact on the systems.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle PeopleSoft Enterprise PeopleTools and related modules allow complete system takeover, unauthorized data modification, and privilege escalation.
- Who is affected
- Deployments running PeopleTools versions 8.61-8.63 and 9.1-9.2 accessible via network.
- Urgency
- High urgency; allows complete system compromise without authentication or with low privileges.
- Action
- Apply Oracle security patches immediately for the affected PeopleTools versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PeopleSoft Enterprise PeopleTools
Get an email when a new PeopleSoft Enterprise PeopleTools advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0316
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-607420.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608210.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608310.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608560.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608730.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608790.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608830.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608840.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-609020.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-609670.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-60742 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60831 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60856 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60873 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60879 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60883 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60884 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60902 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60967 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60975 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61307 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70861 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71092 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71112 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Oracle PeopleSoft: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle PeopleSoft (August 19, 2026)cert-fr-avis
- highCVE-2026-71112: Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (co…nvd
- highCVE-2026-71092: Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSo…nvd
- highCVE-2026-70861: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleS…nvd
- highCVE-2026-61307: Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle Peo…nvd
- highCVE-2026-60975: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60967: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60902: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- mediumCVE-2026-60884: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60883: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
- highCVE-2026-60879: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Or…2026-08-19
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services2026-08-19
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Manager2026-08-19