Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits a low‑privilege attacker with network access to HTTP requests against Oracle PeopleSoft Enterprise PeopleTools. Exploitation requires human interaction from a non‑attacker user, but once triggered the attacker can unauthorized update, insert or delete data and read a subset of accessible data. The impact is a compromise of integrity and confidentiality of PeopleSoft data, but does not provide complete system takeover.

Affected Systems

Oracle's PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 reflects moderate severity with confidentiality and integrity impacts. The EPSS score is below 1 %, indicating that the likelihood of public exploitation is very low at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely to occur over the network via HTTP, requiring low authentication privileges and the cooperation of a non‑attacker user.

Generated by OpenCVE AI on August 2, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for CVE-2026‑47048 as detailed in the July 2026 security alert
  • Restrict HTTP access to PeopleSoft Enterprise PeopleTools from untrusted networks or use a firewall to mitigate remote exploitation
  • Implement role‑based access controls to enforce least privilege, ensuring users cannot perform unauthorized updates, inserts, or deletes

Generated by OpenCVE AI on August 2, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title PeopleSoft PeopleTools HTTP Authorization Bypass Enabling Unauthorized Data Modification

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise PeopleTools Data Access Vulnerability via HTTP
Weaknesses CWE-284

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise PeopleTools Data Access Vulnerability via HTTP
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:30:59.819Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47048

cve-icon Vulnrichment

Updated: 2026-07-23T15:30:55.024Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')