Exploitable Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Process Scheduler
CVE-2026-47017

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47017?

An exploitable input validation vulnerability exists in the Process Scheduler component of Oracle's PeopleSoft Enterprise PeopleTools. This flaw allows low-privileged attackers with network access via HTTP to initiate unauthorized actions that require human interaction from a user other than the attacker. The consequence of a successful exploit includes the unauthorized creation, deletion, or modification of critical data across all accessible datasets within PeopleSoft Enterprise PeopleTools. This vulnerability may also lead to significant impacts on other products related to PeopleSoft, expanding the potential risk surface significantly.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.