
That gap stopped being an audit-season embarrassment on August 18. CVE-2026-60879: CVSS 8.8, PeopleTools 8.61-8.63, low-privileged authenticated user to full takeover. Not an admin. Any account holding a role it never needed.
Post summary
The text announces CVE-2026-60879, detailing its CVSS score, affected PeopleTools versions, and the fact that any low‑privileged authenticated user can achieve full takeover.
