Oracle disclosed a critical, unauthenticated remote vulnerability in the Business Interlink component of PeopleSoft Enterprise PeopleTools that allows full takeover of affected systems over HTTP.
What Is It
CVE-2026-60821 is a vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful exploitation results in takeover of PeopleSoft Enterprise PeopleTools.
It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, exploitability subscore 3.9, impact subscore 5.9.
Why It Matters
Every factor in the vector points the wrong way for defenders: network attack vector, low attack complexity, no privileges required, and no user interaction. Confidentiality, integrity, and availability impacts are all rated High, consistent with Oracle's own language of complete product takeover rather than partial data exposure.
PeopleSoft deployments typically front HR, finance, and student information systems, and the affected component is reachable over HTTP. There is no authentication barrier to raise the bar for an attacker.
This CVE does not currently appear in the CISA Known Exploited Vulnerabilities catalog in the supplied data, and no active exploitation has been confirmed in the source material. The absence of a KEV listing is not evidence of safety; it simply means exploitation has not been catalogued as of this writing.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: PeopleSoft Enterprise PeopleTools
- Component: Business Interlink
- Affected versions: 8.61 through 8.63 (inclusive)
No CPE entries were published with the record at the time of disclosure.
Patch Status
The CVE was published on 2026-08-18 with NVD status Received, meaning NVD analysis was still pending. Oracle issues Critical Patch Updates on a quarterly cycle; January, April, July and October. Because the July 2026 CPU predates this record's publication, the next scheduled quarterly release is October 2026, and Oracle may also address the issue through an out-of-cycle Security Alert; the supplied data does not identify which release carries the fix. Administrators running PeopleTools 8.61–8.63 should confirm the applicable patch against Oracle's current advisory listing before planning remediation. No CISA-mandated required action or remediation deadline applies, as the CVE is not in the KEV catalog per the supplied data.
Sources
- Oracle Critical Patch Update Advisory: https://www.oracle.com/security-alerts/cspuaug2026.html
- Oracle Security Alerts index (current advisory listing): https://www.oracle.com/security-alerts/
- NVD, CVE-2026-60821: https://nvd.nist.gov/vuln/detail/CVE-2026-60821