Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle PeopleSoft Enterprise PeopleTools’ OpenSearch Dashboards component permits an unauthenticated attacker to exploit the web interface over HTTP. The vulnerability does not require prior authentication but does require a human to interact with the GUI, allowing the attacker to compromise administrative processes and potentially gain access to all data stored in the PeopleSoft database. The primary consequence is the confidential disclosure of critical business information, as the CVSS vector indicates no privileges are needed and only user interaction is required.

Affected Systems

Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected. The weakness resides in the OpenSearch Dashboards module of these releases. No other vendors or product lines are listed as impacted.

Risk and Exploitability

The CVSS base score of 7.4 places this issue in the high‑to‑critical severity range. However, the EPSS score of less than 1% suggests it is currently unlikely to see widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, but the scope change clause means that a successful compromise could impact additional PeopleSoft applications linked to the affected component. An attacker would need network access to the affected HTTP service and a human user to initiate the exploit, reducing immediate threat but remaining a significant risk if daily operations require user interaction with the dashboards.

Generated by OpenCVE AI on August 4, 2026 at 05:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle PeopleSoft patch that addresses the OpenSearch Dashboards vulnerability in versions 8.61 and 8.62.
  • Restrict inbound HTTP traffic to the PeopleSoft instance to a limited set of trusted IP addresses or VPN connections.
  • Disable or remove the OpenSearch Dashboards component if it is not required for business operations to eliminate the attack surface.
  • Enhance logging and monitoring of HTTP requests to the affected interfaces, and set up alerts for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in PeopleSoft OpenSearch Dashboards Leading to Confidential Data Exposure

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in PeopleSoft OpenSearch Dashboards Leading to Confidential Data Exposure

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Sensitive Data via OpenSearch Dashboards in Oracle PeopleSoft
Weaknesses CWE-284

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Sensitive Data via OpenSearch Dashboards in Oracle PeopleSoft
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:38.595Z

Reserved: 2026-05-18T15:55:10.317Z

Link: CVE-2026-47026

cve-icon Vulnrichment

Updated: 2026-07-23T15:28:13.761Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')