
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21951 is a Cross-Site Scripting (XSS) vulnerability in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools. It affects supported versions 8.60, 8.61, and 8.62. The vulnerability was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update (CPU). It carries a CVSS v3.1 base score of 6.1 (Medium), reflecting a network-accessible, unauthenticated attack requiring user interaction with a changed scope (Oracle CPU Jan 2026).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An unauthenticated remote attacker can exploit this flaw via HTTP by crafting a malicious request or link targeting the Integration Broker component; successful exploitation requires a victim user to interact with the attacker-controlled content (e.g., clicking a link). The scope change in the CVSS scoring indicates that a successful attack can impact resources beyond the vulnerable PeopleTools component itself, potentially affecting other connected systems or products. No public proof-of-concept or detailed technical write-up has been identified at this time (Oracle CPU Jan 2026).
Successful exploitation allows an unauthenticated attacker to perform unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data, as well as unauthorized update, insert, or delete operations on some accessible data. The scope change means attacks may significantly impact additional products beyond PeopleTools itself, increasing the potential blast radius. Availability is not impacted by this vulnerability (Oracle CPU Jan 2026).
<script>, %3Cscript%3E, javascript:) in query parameters or request bodies.Oracle has released patches for CVE-2026-21951 as part of the January 2026 Critical Patch Update; organizations running PeopleSoft Enterprise PeopleTools versions 8.60, 8.61, or 8.62 should apply the relevant patches immediately. As a temporary workaround, Oracle recommends implementing network access controls to restrict HTTP access to PeopleSoft Enterprise PeopleTools to trusted networks only. Additionally, organizations should educate users about social engineering and suspicious links, and monitor Integration Broker components for anomalous activity. Oracle strongly advises against relying on workarounds as a long-term solution (Oracle CPU Jan 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."