Search/CVE-2026-60873
CVE — High

CVE-2026-60873

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to…

CVSS v3.1
7.2 HIGH
EPSS
0.13%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 20, 2026Aug 23, 2026
0.01pp
0.12% → 0.13% over 3 tracked changes
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredHIGH
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityLOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
Aug 18, 2026
Disclosure — published as a CVE record.