Summary
CVE-2026-60742 is a high-severity vulnerability in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools that allows an unauthenticated, network-based attacker to compromise the platform over HTTP. Oracle rates the flaw 8.1 (HIGH) and states that successful exploitation can result in a complete takeover of PeopleSoft Enterprise PeopleTools, affecting confidentiality, integrity, and availability. Oracle disclosed the issue in its August 2026 Critical Patch Update.
Technical details
- Root cause lies in the PIA Core Technology component of PeopleSoft Enterprise PeopleTools; Oracle has not published further technical detail on the underlying mechanism.
- The vulnerability is remotely exploitable over HTTP without requiring any authentication or user interaction.
- Oracle characterizes the flaw as "difficult to exploit," corresponding to a High attack complexity (AC:H) rating.
- Successful exploitation can result in complete takeover of the affected PeopleTools deployment, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for August 2026, which addresses CVE-2026-60742 in PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63.
- If patching cannot be performed immediately, restrict network access to the PeopleSoft Internet Architecture (PIA) interface to trusted networks only, and monitor internet-facing PeopleSoft instances closely until the patch is applied.

