Unauthorized Data Access Vulnerability in Oracle PeopleSoft
CVE-2026-47049

4.9MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47049?

A vulnerability exists in Oracle's PeopleSoft Enterprise PeopleTools that allows an attacker with high privileges and network access via HTTP to potentially compromise the system. This security gap affects versions 8.61 and 8.62, enabling unauthorized access to critical data within the PeopleSoft environment. Successful exploitation can lead to significant data exposure, risking sensitive information management and threatening organizational data integrity.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.