LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34309

CVE-2026-34309 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 21, 2026

Oracle PeopleSoft PeopleTools - Broken Access Control

Published: April 21, 2026Updated: April 21, 2026Remote Exploitable

Overview

Oracle PeopleSoft PeopleTools 8.61-8.62 contains a broken access control vulnerability in Security component, letting low privileged attackers with network HTTP access modify or access critical data, exploit requires low privilege network access.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Attackers can create, delete, or modify critical data and gain unauthorized access to all accessible PeopleSoft data.

Mitigation

Update to the latest available version beyond 8.62.

Details

CVE ID
CVE-2026-34309
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N