Multiples vulnérabilités dans Oracle PeopleSoft (19 août 2026)
A French security advisory from CERT-FR details multiple vulnerabilities within Oracle PeopleSoft versions 9.2 and 8.61-8.63. These flaws could lead to data breaches, data integrity issues, denial of service attacks, and remote code execution, requiring immediate patching to mitigate the risks.
CERT-FR has identified several vulnerabilities affecting Oracle PeopleSoft. These vulnerabilities can result in data breaches, compromising the integrity of stored data, and potentially causing denial of service conditions. Specifically, the advisory highlights issues that could allow for remote code execution, enabling attackers to gain significant control over affected systems. The vulnerabilities are present across various PeopleSoft components, including Common Application Objects, FIN Common Objects Brazil, FIN Common Objects, and Lease Administration. Affected versions include PeopleSoft Enterprise CC Common Application Objects version 9.2, PeopleSoft Enterprise FIN Common Objects Brazil version 9.1, PeopleSoft Enterprise FIN Common Objects version 9.2, PeopleSoft Enterprise PeopleTools version 8.61, PeopleSoft Enterprise PeopleTools versions 8.61-8.63, and related components. The advisory directs users to consult the linked Oracle security alert for detailed information and remediation steps. The CVE identifiers are CVE-2026-60742, CVE-2026-60821, CVE-2026-60831, CVE-2026-60856, CVE-2026-60873, CVE-2026-60879, CVE-2026-60883, CVE-2026-60884, CVE-2026-60902, CVE-2026-60967, CVE-2026-60975, CVE-2026-61307, and CVE-2026-70861, CVE-2026-71092, CVE-2026-71112.