Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60873

CVE-2026-60873: PeopleSoft PeopleTools Escalation Flaw

CVE-2026-60873 is a privilege escalation vulnerability in Oracle PeopleSoft Enterprise PeopleTools Data Mover component affecting versions 8.61-8.63. This article covers technical details, attack vectors, and mitigations.

Updated:

CVE-2026-60873 Overview

CVE-2026-60873 affects the Data Mover component of Oracle PeopleSoft Enterprise PeopleTools. The flaw impacts supported versions 8.61 through 8.63. Exploitation requires a high-privileged attacker with local logon access to the infrastructure running PeopleTools, plus user interaction from a second party. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, complete disclosure of all PeopleTools-accessible data, and partial denial of service. The vulnerability carries a scope change, meaning impact can extend to components beyond PeopleTools itself. Oracle addressed the issue in the August 2026 Critical Patch Update.

Critical Impact

Local attackers with elevated privileges can compromise PeopleTools data confidentiality and integrity, and cause partial service disruption across dependent Oracle products through scope change.

Affected Products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61
  • Oracle PeopleSoft Enterprise PeopleTools 8.62
  • Oracle PeopleSoft Enterprise PeopleTools 8.63

Discovery Timeline

  • 2026-08-18 - CVE-2026-60873 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-60873

Vulnerability Analysis

The vulnerability resides in the Data Mover component of Oracle PeopleSoft Enterprise PeopleTools. Data Mover is an administrative utility used to import, export, and manipulate PeopleSoft database contents through script files. The weakness is categorized under [CWE-284] Improper Access Control.

Oracle classifies this flaw as difficult to exploit. The attacker must already hold high privileges on the host where PeopleTools executes and must convince another user to perform an action that triggers the vulnerable code path. Once triggered, the attacker gains full read and write access to data reachable by PeopleTools.

Because the vulnerability crosses a security scope boundary, impact extends beyond PeopleTools to additional Oracle products that rely on or trust the compromised component. This amplifies the damage of a single administrative compromise.

Root Cause

The root cause is improper access control within Data Mover script handling. The component fails to properly restrict operations that a privileged local actor can perform when a second user interacts with the tool, allowing unauthorized data operations across trust boundaries.

Attack Vector

The attack vector is local. An attacker with a valid high-privileged logon to the PeopleTools infrastructure stages a malicious Data Mover script or configuration. When a separate user with the required interaction runs or approves the operation, the attacker's payload executes with elevated data-access rights and produces the confidentiality, integrity, and partial availability impacts described in the advisory.

No public proof-of-concept code or exploit exists at the time of publication. Refer to the Oracle Security Alert for vendor technical detail.

Detection Methods for CVE-2026-60873

Indicators of Compromise

  • Unexpected execution of psdmt.exe or Data Mover command-line invocations outside of scheduled administrative windows.
  • New or modified Data Mover script files (.dms) in PeopleTools directories that were not authored by change-approved administrators.
  • Anomalous bulk read, export, or delete operations against PeopleSoft database tables originating from PeopleTools service accounts.

Detection Strategies

  • Baseline legitimate Data Mover usage per host and alert on deviations in execution frequency, invoking user, and script source path.
  • Monitor PeopleTools application server and database audit logs for administrative actions correlated with interactive logon sessions of privileged users.
  • Correlate file integrity monitoring events on Data Mover script directories with database write activity to detect script tampering followed by execution.

Monitoring Recommendations

  • Enable and centralize PeopleSoft audit logging, Windows or Linux logon events, and database DDL/DML auditing for PeopleTools service accounts.
  • Track user-interaction events such as approvals or launches performed by administrators after another user staged Data Mover artifacts.
  • Forward host and application telemetry to a SIEM for cross-source correlation and long-term retention.

How to Mitigate CVE-2026-60873

Immediate Actions Required

  • Apply the fixes published in the Oracle August 2026 Critical Patch Update to all PeopleTools 8.61, 8.62, and 8.63 deployments.
  • Inventory hosts running PeopleTools and identify accounts with local logon rights to those systems; reduce that set to the minimum required.
  • Review recent Data Mover script executions and file changes for signs of tampering before patching.

Patch Information

Oracle released the fix in the August 2026 Critical Patch Update. Administrators should download and deploy the patches referenced in the Oracle Security Alert for PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63.

Workarounds

  • Restrict interactive logon to PeopleTools infrastructure to a small, audited set of administrators until patches are applied.
  • Require multi-person review and change-control approval before executing any Data Mover script in production environments.
  • Enforce strict file system permissions on Data Mover script directories so only vetted operators can create or modify .dms files.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.