
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21938 is a cross-site scripting (XSS) or similar web-based injection vulnerability affecting the Portal component of Oracle PeopleSoft Enterprise PeopleTools. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026, and affects supported versions 8.60, 8.61, and 8.62. The vulnerability is easily exploitable by unauthenticated attackers over HTTP but requires human interaction (e.g., a user clicking a malicious link), and successful exploitation can impact additional products beyond the directly affected system (scope change). It carries a CVSS v3.1 base score of 6.1 (Medium) per Oracle's advisory, though Feedly's data notes a slightly different scoring of 5.4 depending on scope interpretation (Oracle CPU Jan 2026).
The vulnerability resides in the Portal component of Oracle PeopleSoft Enterprise PeopleTools and is consistent with a Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) class of flaw (CWE-79 or CWE-352), given that exploitation requires human interaction, involves a scope change affecting additional products, and results in unauthorized data read/write without requiring authentication. An unauthenticated attacker with network access via HTTP can craft a malicious request or link that, when interacted with by a victim user, causes unauthorized operations to be performed in the context of the PeopleSoft Portal. No public proof-of-concept code or detailed technical write-up has been identified at this time (Oracle CPU Jan 2026).
Successful exploitation allows an unauthenticated attacker to perform unauthorized update, insert, or delete operations on a subset of PeopleSoft Enterprise PeopleTools accessible data, as well as unauthorized read access to a subset of that data. The scope change noted in the CVSS scoring indicates that the impact can extend beyond the directly vulnerable PeopleTools component to affect other products or systems within the same environment. Availability is not impacted, but the confidentiality and integrity risks are relevant for organizations relying on PeopleSoft for sensitive HR, financial, or operational data (Oracle CPU Jan 2026).
Oracle has released patches for all affected versions (8.60, 8.61, and 8.62) as part of the Oracle Critical Patch Update for January 2026, released on January 20, 2026. Organizations should apply the CPU January 2026 patches to their PeopleSoft Enterprise PeopleTools installations as soon as possible. As interim mitigations, Oracle recommends blocking network access to the affected Portal component where feasible, implementing security awareness training to reduce susceptibility to social engineering, and applying email filtering to reduce delivery of malicious links. Oracle strongly advises against relying on network-level workarounds as a long-term solution (Oracle CPU Jan 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."