PatchSiren cyber security CVE debrief
CVE-2026-60873 Oracle Corporation CVE debrief
The PeopleSoft Enterprise PeopleTools product, specifically versions 8.61-8.63, contains a difficult-to-exploit vulnerability that allows high privileged attackers with logon access to compromise the system. This vulnerability, tracked as CVE-2026-60873, requires human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, indicating high severity. Administrators and security teams should be aware of the potential impact on confidentiality, integrity, and availability.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise PeopleTools
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-21
Who should care
Administrators of PeopleSoft Enterprise PeopleTools versions 8.61-8.63, security teams monitoring for potential high privileged attacks, and those responsible for applying vendor patches should be aware of this vulnerability. Additionally, operators managing affected product deployments and security teams responsible for vulnerability management should take note of the potential impact on confidentiality, integrity, and availability. Human interaction is required for successful attacks, and scope change is possible, impacting additional products. Defenders should verify system logs for suspicious activity and monitor for unauthorized data access. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then. Security teams should prioritize patching and compensating controls to limit the attack surface. Vulnerability management teams should track exceptions and retest remediated assets. Monitoring and detection teams should review relevant logs for exposed assets that need extra review. Asset inventory managers should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Change management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Source tracking should be implemented to monitor for potential attacks. Rollback/change windows should be considered for affected systems. Exposure review should be conducted to identify potential vulnerabilities. Vendor patch guidance should be followed to ensure timely patching of affected systems. The debrief provides an executive overview of the vulnerability, its likely operational impact, and source-confidence limits. The technical summary provides affected product context and defensive impact. Evidence notes provide source grounding and evidence limits. The recommended actions provide a comprehensive plan for defenders to address the vulnerability. The defensive priority is high due to the potential impact on confidentiality, integrity, and availability. The CVE-202
Technical summary
The vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61-8.63 allows high privileged attackers with logon access to compromise the system. Successful attacks require human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, with a vector of (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L). Defenders should focus on limiting high privileged attacker access and monitoring for unauthorized data access and system modifications.
Defensive priority
High privileged attackers may exploit this vulnerability in PeopleSoft Enterprise PeopleTools, impacting confidentiality, integrity, and availability.
Recommended defensive actions
- Inventory PeopleSoft Enterprise PeopleTools versions 8.61-8.63 and apply vendor patches
- Implement compensating controls to limit high privileged attacker access
- Monitor for unauthorized data access and system modifications
- Verify system logs for suspicious activity
- Restrict logon access to infrastructure where PeopleSoft Enterprise PeopleTools executes
Evidence notes
The vulnerability exists in PeopleSoft Enterprise PeopleTools versions 8.61-8.63. Human interaction is required for successful attacks. Scope change is possible, impacting additional products. Defenders should verify system logs for suspicious activity and monitor for unauthorized data access. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then.
Official resources
-
CVE-2026-60873 CVE record
CVE.org
-
CVE-2026-60873 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:46.070Z and has not been modified since then.