CVE-2026-60967

8.8

Oracle · PeopleSoft Enterprise PeopleTools

A vulnerability in the nVision component of Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker to compromise the system via network-based HTTP interaction.

Executive summary

An unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools poses a critical risk of full system takeover.

Vulnerability

This vulnerability affects the nVision component and allows an unauthenticated attacker with network access to execute malicious actions. Successful exploitation requires user interaction from a legitimate user, potentially leading to a complete takeover of the PeopleSoft environment.

Business impact

With a CVSS score of 8.8, this vulnerability represents a high-severity threat to business operations. A successful compromise could lead to unauthorized access to sensitive financial and operational data, potential data exfiltration, and significant service disruption, which would result in substantial reputational and financial damage.

Remediation

Immediate Action: Apply the security updates provided by Oracle in the August 2026 Critical Patch Update.

Proactive Monitoring: Review access logs for anomalous HTTP requests targeting the nVision component and monitor for unexpected user account activity.

Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter malicious traffic and block unauthorized HTTP requests directed at the PeopleSoft environment until patches are applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for full system compromise, organizations running the affected versions of PeopleSoft Enterprise PeopleTools must prioritize the deployment of the vendor-supplied security patches. Immediate patching is the only effective way to neutralize the risk associated with this unauthenticated attack vector.

More Oracle CVEs