📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global ransomware Multiple sectors CRITICAL 15m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 1h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h Global ransomware Multiple sectors CRITICAL 15m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 1h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h Global ransomware Multiple sectors CRITICAL 15m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 1h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h
Vulnerabilities

CVE-2026-34277

Medium
Published: Apr 21, 2026  ·  Modified: Apr 22, 2026  ·  Source: NVD
CVSS v3
6.6
🔗 NVD Official
📄 Description (English)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).

🤖 AI Executive Summary

A medium-severity vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.62 allows high-privileged attackers with network access to compromise the system via HTTP. Successful exploitation can result in unauthorized data access, modification, and partial denial of service affecting PeopleSoft and dependent systems.

📄 Description (Arabic)

تؤثر هذه الثغرة على مكون Fluid Core في PeopleSoft Enterprise PeopleTools وتتطلب امتيازات عالية للاستغلال. يمكن للمهاجمين الوصول إلى البيانات وتعديلها وحذفها بشكل غير مصرح به، مما يؤثر على سرية وتكامل البيانات. قد يؤدي الهجوم أيضاً إلى تعطيل جزئي للخدمة والأنظمة المرتبطة بها.

🤖 ملخص تنفيذي (AI)

ثغرة متوسطة الخطورة في منتج Oracle PeopleSoft Enterprise PeopleTools الإصدارات 8.61-8.62 تسمح للمهاجمين ذوي الامتيازات العالية بالوصول عبر الشبكة. يمكن للهجمات الناجحة أن تؤدي إلى وصول غير مصرح به للبيانات وتعديلها وتعطيل جزئي للخدمة.

🤖 AI Intelligence Analysis Analyzed: May 10, 2026 21:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
banking government healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
7.0
/ 10.0
🔧 Remediation Steps (English)
Immediately upgrade PeopleSoft Enterprise PeopleTools to versions beyond 8.62 or apply Oracle's security patches. Restrict HTTP network access to PeopleTools systems using firewall rules and network segmentation. Implement strong authentication mechanisms and monitor privileged user activities. Disable unnecessary Fluid Core features if not required for operations.
🔧 خطوات المعالجة (العربية)
قم بترقية PeopleSoft Enterprise PeopleTools فوراً إلى إصدارات أحدث من 8.62 أو تطبيق تصحيحات أمان Oracle. قيد الوصول عبر HTTP باستخدام قواعد جدار الحماية والفصل الشبكي. طبق آليات مصادقة قوية ومراقبة أنشطة المستخدمين ذوي الامتيازات. عطل ميزات Fluid Core غير الضرورية إن لم تكن مطلوبة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.7.1.1 A.9.2.1 A.9.2.5 A.12.4.1
🔵 SAMA CSF
ID.AM-2 PR.AC-1 PR.AC-3 DE.CM-1
🟡 ISO 27001:2022
A.6.1.1 A.9.1.1 A.9.2.1 A.9.4.3 A.12.4.1
📊 CVSS Score
6.6
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredH — High
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.6
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-04-21
Source Feed nvd
🇸🇦 Saudi Risk Score
7.0
/ 10.0 — Saudi Risk
Priority: HIGH
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.