Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Security Component
CVE-2026-47048

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47048?

A security vulnerability exists within the Oracle PeopleSoft Enterprise PeopleTools product, specifically affecting the security component. This vulnerability allows an attacker with low privileges and network access via HTTP to exploit the system, potentially compromising the integrity of sensitive data. Successful exploitation necessitates human interaction from a victim, leading to unauthorized updates, insertions, or deletions of accessible data. Furthermore, it may grant unauthorized read access to certain subsets of data, amplifying the risk of data exposure. The issue impacts supported versions 8.61 and 8.62 and could also affect additional products associated with PeopleSoft Enterprise PeopleTools.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.