
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34309 is an improper access control vulnerability in the Security component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. It allows a low-privileged attacker with network access via HTTP to perform unauthorized read and write operations on critical PeopleTools data. The vulnerability was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update (CPU). It carries a CVSS v3.1 base score of 8.1 (High) (Oracle CPU Apr 2026, GitHub Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control), residing in the Security component of PeopleSoft Enterprise PeopleTools. An attacker with low-level authenticated access can exploit the flaw over HTTP without requiring user interaction or elevated privileges, indicating that authorization enforcement within the Security component is insufficient or incorrectly implemented. The low attack complexity means no special conditions or race conditions are required to trigger the vulnerability. No detailed technical write-up or public proof-of-concept code has been published as of the time of this report (Oracle CPU Apr 2026, GitHub Advisory).
Successful exploitation allows an attacker to gain complete unauthorized read access to all PeopleSoft Enterprise PeopleTools accessible data, as well as the ability to create, delete, or modify critical data within the platform. The vulnerability has high confidentiality and integrity impacts, though availability is not affected. Given that PeopleSoft is commonly used for enterprise HR, finance, and supply chain operations, unauthorized data access or modification could expose sensitive employee, financial, or operational records and disrupt business processes (Oracle CPU Apr 2026, GitHub Advisory).
Oracle has addressed this vulnerability in the April 2026 Critical Patch Update (CPU), released April 21, 2026. Organizations running PeopleSoft Enterprise PeopleTools versions 8.61 or 8.62 should apply the relevant patches from the April 2026 CPU immediately. As a temporary workaround while patches are being deployed, Oracle recommends restricting network access to PeopleTools HTTP interfaces to trusted networks only. Oracle strongly advises against relying on network-level mitigations as a long-term solution (Oracle CPU Apr 2026, GitHub Advisory).
The vulnerability received limited but standard coverage following Oracle's April 2026 CPU release, with aggregator sites such as Red Packet Security and VulDB cataloging the advisory. Social media mentions were observed on Mastodon and Bluesky shortly after disclosure, consistent with routine CPU coverage. No notable independent researcher commentary or significant media coverage specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."