Security Vulnerability in Oracle PeopleSoft Enterprise PeopleTools
CVE-2026-47051

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47051?

A security vulnerability exists in Oracle's PeopleSoft Enterprise PeopleTools, specifically in its Security component. This vulnerability allows a low-privileged attacker with HTTP network access to compromise the integrity of PeopleSoft Enterprise PeopleTools. Successful exploitation requires user interaction from someone other than the attacker, which could lead to unauthorized modifications to accessible data, including the ability to update, insert, or delete records. Furthermore, there is potential for unauthorized read access to certain datasets within PeopleSoft Enterprise PeopleTools. The vulnerabilities in PeopleTools may also have implications for other related products, expanding the potential scope of impact.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.