Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-73955

CVE-2026-73955: PeopleSoft PeopleTools Auth Bypass Flaw

CVE-2026-73955 is an authentication bypass vulnerability in Oracle PeopleSoft Enterprise PeopleTools that enables unauthorized data access and modification. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-73955 Overview

CVE-2026-73955 is a high-severity vulnerability in the Charting component of Oracle PeopleSoft Enterprise PeopleTools. The flaw affects supported versions 8.61 through 8.63. A low-privileged attacker with network access via HTTP can exploit this vulnerability, but successful attacks require user interaction from a person other than the attacker. Exploitation can result in unauthorized creation, deletion, or modification of critical PeopleSoft data, along with unauthorized read access to all PeopleSoft Enterprise PeopleTools accessible data. The vulnerability is classified under [CWE-284] Improper Access Control.

Critical Impact

Successful exploitation grants attackers read and write access to all PeopleSoft Enterprise PeopleTools accessible data, compromising both confidentiality and integrity.

Affected Products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61
  • Oracle PeopleSoft Enterprise PeopleTools 8.62
  • Oracle PeopleSoft Enterprise PeopleTools 8.63

Discovery Timeline

  • 2026-09-15 - CVE CVE-2026-73955 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-73955

Vulnerability Analysis

The vulnerability resides in the Charting component of Oracle PeopleSoft Enterprise PeopleTools. It falls under improper access control ([CWE-284]), meaning the component fails to correctly restrict access to resources or actions that should require stronger authorization. An authenticated attacker with low privileges can leverage this weakness to reach data and operations that should remain out of scope for their role.

Exploitation requires interaction from a legitimate user other than the attacker. This user interaction requirement is consistent with attacks that trick a victim into loading a crafted URL or interacting with attacker-controlled content while authenticated to a PeopleSoft session.

Root Cause

The root cause is improper access control within the Charting component. The component does not adequately validate whether the requesting principal is authorized to perform the requested operation, allowing a low-privileged user to reach functionality that impacts confidentiality and integrity across all PeopleSoft Enterprise PeopleTools accessible data.

Attack Vector

The attack originates over the network via HTTP. An authenticated attacker with low privileges crafts a request or content targeting the Charting component and induces a victim user to trigger the vulnerable code path. Because the scope is unchanged and availability is not impacted, the attack focuses on data disclosure and unauthorized modification rather than service disruption. Refer to the Oracle Security Alert September 2026 for vendor guidance.

Detection Methods for CVE-2026-73955

Indicators of Compromise

  • Unexpected HTTP requests to PeopleSoft Charting component endpoints originating from low-privileged user sessions.
  • Anomalous read or write activity against PeopleTools data stores initiated from Charting-related URIs.
  • Session activity involving Charting resources immediately following a user clicking an externally supplied link.

Detection Strategies

  • Review PeopleSoft web server access logs for unusual query parameters or POST payloads directed at Charting endpoints.
  • Correlate authenticated user sessions with subsequent access to data outside their normal role scope.
  • Baseline expected Charting usage per role and alert on deviations that suggest privilege boundary crossing.

Monitoring Recommendations

  • Enable verbose audit logging within PeopleSoft for data create, modify, and delete events.
  • Forward PeopleSoft application and web tier logs to a centralized SIEM for correlation with identity events.
  • Monitor outbound links delivered to PeopleSoft users through email or collaboration tools that could serve as the user-interaction vector.

How to Mitigate CVE-2026-73955

Immediate Actions Required

  • Apply the patches referenced in the Oracle Security Alert September 2026 to all affected PeopleTools 8.61, 8.62, and 8.63 deployments.
  • Inventory internet-exposed PeopleSoft instances and prioritize them for immediate patching.
  • Review recent authentication and data access logs for signs of exploitation while remediation is scheduled.

Patch Information

Oracle addressed this vulnerability in the September 2026 Security Alert cycle. Administrators should consult the Oracle Security Alert September 2026 for the specific patch bundle applicable to their PeopleTools version and follow the vendor upgrade procedures.

Workarounds

  • Restrict network access to the PeopleSoft web tier so only trusted networks and VPN clients can reach the application.
  • Educate PeopleSoft users on the risk of clicking untrusted links while authenticated to the application.
  • Enforce least privilege for PeopleSoft roles so that even a compromised low-privileged account minimizes reachable data.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.