PT-2026-3708 · Oracle · Peoplesoft Enterprise Hcm Human Resources

Published

2026-01-20

·

Updated

2026-01-21

·

CVE-2026-21961

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle PeopleSoft Enterprise HCM Human Resources version 9.2
Description A flaw exists in the PeopleSoft Enterprise HCM Human Resources component, specifically within Company Dir / Org Chart Viewer and Employee Snapshot. This issue allows a network attacker, without needing to authenticate, to compromise the system. Exploitation requires interaction from a user other than the attacker. Successful exploitation could lead to unauthorized data modification, insertion, or deletion, as well as unauthorized read access to data within PeopleSoft Enterprise HCM Human Resources. The attack may also impact additional products.
Recommendations Update PeopleSoft Enterprise HCM Human Resources version 9.2 to a newer, fixed version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-00991
CVE-2026-21961

Affected Products

Peoplesoft Enterprise Hcm Human Resources