PatchSiren cyber security CVE debrief
CVE-2026-60873 Oracle Corporation CVE debrief
The PeopleSoft Enterprise PeopleTools product, specifically versions 8.61-8.63, contains a difficult-to-exploit vulnerability that allows high privileged attackers with logon access to compromise the system. This vulnerability, tracked as CVE-2026-60873, requires human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, indicating high severity. Administrators and security teams should be aware of the potential impact on confidentiality, integrity, and availability.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise PeopleTools
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-21
Who should care
Administrators of PeopleSoft Enterprise PeopleTools versions 8.61-8.63, security teams monitoring for potential high privileged attacks, and those responsible for applying vendor patches should be aware of this vulnerability. Additionally, operators managing affected product deployments and security teams responsible for vulnerability management should take note of the potential impact on confidentiality, integrity, and availability. Human interaction is required for successful attacks, and scope change is possible, impacting additional products. Defenders should verify system logs for suspicious activity and monitor for unauthorized data access. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then. Security teams should prioritize patching and compensating controls to limit the attack surface. Vulnerability management teams should track exceptions and retest remediated assets. Monitoring and detection teams should review relevant logs for exposed assets that need extra review. Asset inventory managers should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Change management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Source tracking should be implemented to monitor for potential attacks. Rollback/change windows should be considered for affected systems. Exposure review should be conducted to identify potential vulnerabilities. Vendor patch guidance should be followed to ensure timely patching of affected systems. The debrief provides an executive overview of the vulnerability, its likely operational impact, and source-confidence limits. The technical summary provides affected product context and defensive impact. Evidence notes provide source grounding and evidence limits. The recommended actions provide a comprehensive plan for defenders to address the vulnerability. The defensive priority is high due to the potential impact on confidentiality, integrity, and availability. The CVE-202
Technical summary
The vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61-8.63 allows high privileged attackers with logon access to compromise the system. Successful attacks require human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, with a vector of (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L). Defenders should focus on limiting high privileged attacker access and monitoring for unauthorized data access and system modifications.
Defensive priority
High privileged attackers may exploit this vulnerability in PeopleSoft Enterprise PeopleTools, impacting confidentiality, integrity, and availability.
Recommended defensive actions
- Inventory PeopleSoft Enterprise PeopleTools versions 8.61-8.63 and apply vendor patches
- Implement compensating controls to limit high privileged attacker access
- Monitor for unauthorized data access and system modifications
- Verify system logs for suspicious activity
- Restrict logon access to infrastructure where PeopleSoft Enterprise PeopleTools executes
Evidence notes
The vulnerability exists in PeopleSoft Enterprise PeopleTools versions 8.61-8.63. Human interaction is required for successful attacks. Scope change is possible, impacting additional products. Defenders should verify system logs for suspicious activity and monitor for unauthorized data access. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60873 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60873
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60873 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60873
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspuaug2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.