news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans Oracle PeopleSoft (16 septembre 2026)

HighCVSS 8.8
Summary

Multiple vulnerabilities have been discovered in Oracle PeopleSoft, allowing an attacker to cause a denial of service, data confidentiality compromise, and data integrity issues. These vulnerabilities affect various PeopleSoft components, including the Enterprise CC Common Application Objects, FIN Engineering Brazil, FIN Inventory Brazil, PeopleTools, and PRTL Interaction Hub. Oracle has released a security alert with specific remediation steps.

Oracle has issued a security alert regarding multiple vulnerabilities within its PeopleSoft platform. These vulnerabilities can lead to data integrity compromise, data confidentiality issues, and denial of service attacks. Specifically, the affected products include PeopleSoft Enterprise CC Common Application Objects version 9.2, PeopleSoft Enterprise FIN Engineering Brazil version 9.1, PeopleSoft Enterprise FIN Inventory Brazil version 9.1, PeopleSoft Enterprise PeopleTools versions 8.61 to 8.63, and PeopleSoft Enterprise PRTL Interaction Hub version 9.1. The vulnerabilities are associated with CVE identifiers: CVE-2023-48795, CVE-2023-6918, CVE-2026-25639, CVE-2026-73954, CVE-2026-73955, CVE-2026-73960, CVE-2026-7598, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83018, CVE-2026-83019, CVE-2026-83070, CVE-2026-83147, and CVE-2026-83420. The security alert directs users to the official Oracle security alert for detailed information and remediation steps: https://www.oracle.com/security-alerts/cspusep2026.html.

Read the full article at CERT-FR