Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is tied to the Security component of PeopleSoft Enterprise PeopleTools. An attacker with low privileges and network access over HTTP can conduct the exploit. The flaw permits the attacker to perform unauthorized update, insert or delete operations and read restricted data. These actions compromise the confidentiality and integrity of PeopleSoft data but do not affect availability. The weakness is reachable only through human interaction with a user other than the attacker.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PeopleTools 8.61 and 8.62 are impacted. The products include the PeopleSoft application suite that handles enterprise data. No other versions or vendors are currently listed as affected. Systems running the specified versions must be evaluated for exposure.

Risk and Exploitability

With a CVSS base score of 5.4 the risk is classified as medium severity. The EPSS score is less than 1 %, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based HTTP, requiring low attacker privileges and user interaction from a different individual. The ability to modify or read protected data makes the vulnerability valuable to attackers especially if the end user is a privileged account holder. The description notes a scope change, indicating that successful exploitation may affect additional products beyond PeopleSoft alone.

Generated by OpenCVE AI on August 4, 2026 at 05:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle PeopleSoft security patch for versions 8.61 and 8.62 to address the exposed security component.
  • Restrict HTTP access to PeopleSoft interfaces to trusted networks or enforce firewall rules, limiting exposure of the vulnerable redirect function.
  • Review and configure PeopleSoft application settings to disable or tighten any open redirect functionality, ensuring redirects only use internally validated URLs.

Generated by OpenCVE AI on August 4, 2026 at 05:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Open redirect vulnerability enabling low‑privileged actors to modify and read restricted PeopleSoft data

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise PeopleTools HTTP Access Allows Unauthorized Data Modification and Disclosure
Weaknesses CWE-284
CWE-306

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title PeopleSoft Enterprise PeopleTools HTTP Access Allows Unauthorized Data Modification and Disclosure
Weaknesses CWE-284
CWE-306

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Peopletools
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:28:59.836Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47051

cve-icon Vulnrichment

Updated: 2026-07-23T15:28:54.772Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:10.790

Modified: 2026-07-27T19:33:49.903

Link: CVE-2026-47051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')