CVE-2026-60821Disclosure(oracle / peoplesoft_enterprise_peopletools)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • peoplesoft_enterprise_peopletools

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
peoplesoft_enterprise_peopletools

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-24: 1Technical Details · 2026-08-24: 108-24
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Aaron Engelsrud@AEngelsrud
    Disclosure

    Read CVE-2026-60821 first. CVSS 9.8. Unauthenticated, over HTTP, low complexity, full PeopleTools takeover. Business Interlink — legacy plumbing most sites forgot was still enabled. Affected: 8.61 through 8.63. Including the release Oracle shipped last month.

    Post summary

    The post announces CVE-2026-60821, a high‑impact unauthenticated HTTP-based full takeover of PeopleTools affecting Oracle 8.61‑8.63, with no PoC, exploit, or patch details provided.

    1000040
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclepeoplesoft_enterprise_peopletools---

Explore more