PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60873 Oracle Corporation CVE debrief

The PeopleSoft Enterprise PeopleTools product, specifically versions 8.61-8.63, contains a difficult-to-exploit vulnerability that allows high privileged attackers with logon access to compromise the system. This vulnerability, tracked as CVE-2026-60873, requires human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, indicating high severity. Administrators and security teams should be aware of the potential impact on confidentiality, integrity, and availability.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise PeopleTools
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Administrators of PeopleSoft Enterprise PeopleTools versions 8.61-8.63, security teams monitoring for potential high privileged attacks, and those responsible for applying vendor patches should be aware of this vulnerability. Additionally, operators managing affected product deployments and security teams responsible for vulnerability management should take note of the potential impact on confidentiality, integrity, and availability. Human interaction is required for successful attacks, and scope change is possible, impacting additional products. Defenders should verify system logs for suspicious activity and monitor for unauthorized data access. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then. Security teams should prioritize patching and compensating controls to limit the attack surface. Vulnerability management teams should track exceptions and retest remediated assets. Monitoring and detection teams should review relevant logs for exposed assets that need extra review. Asset inventory managers should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Change management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Source tracking should be implemented to monitor for potential attacks. Rollback/change windows should be considered for affected systems. Exposure review should be conducted to identify potential vulnerabilities. Vendor patch guidance should be followed to ensure timely patching of affected systems. The debrief provides an executive overview of the vulnerability, its likely operational impact, and source-confidence limits. The technical summary provides affected product context and defensive impact. Evidence notes provide source grounding and evidence limits. The recommended actions provide a comprehensive plan for defenders to address the vulnerability. The defensive priority is high due to the potential impact on confidentiality, integrity, and availability. The CVE-202

Technical summary

The vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61-8.63 allows high privileged attackers with logon access to compromise the system. Successful attacks require human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, with a vector of (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L). Defenders should focus on limiting high privileged attacker access and monitoring for unauthorized data access and system modifications.

Defensive priority

High privileged attackers may exploit this vulnerability in PeopleSoft Enterprise PeopleTools, impacting confidentiality, integrity, and availability.

Recommended defensive actions

  • Inventory PeopleSoft Enterprise PeopleTools versions 8.61-8.63 and apply vendor patches
  • Implement compensating controls to limit high privileged attacker access
  • Monitor for unauthorized data access and system modifications
  • Verify system logs for suspicious activity
  • Restrict logon access to infrastructure where PeopleSoft Enterprise PeopleTools executes

Evidence notes

The vulnerability exists in PeopleSoft Enterprise PeopleTools versions 8.61-8.63. Human interaction is required for successful attacks. Scope change is possible, impacting additional products. Defenders should verify system logs for suspicious activity and monitor for unauthorized data access. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then.