Junglewise Threat Intelligence

CVE-2026-47015: Oracle PeopleSoft PeopleTools vulnerability in PIA Core Technology

CVE-2026-47015 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle PeopleTools. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle PeopleSoft's PeopleTools, the underlying technology for PeopleSoft applications. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to unauthorized data changes, information disclosure, or a partial disruption of the PeopleSoft service.

Technical details

A vulnerability in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools (version 8.62) allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is characterized by a 'scope change' (CVSS S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection flaw that allows an attacker to impact components beyond the immediate PeopleTools environment. Exploitation requires human interaction from a person other than the attacker. Successful exploitation can result in unauthorized data manipulation (update, insert, delete), unauthorized read access to a subset of data, and a partial denial of service. The issue is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.62

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-47015
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats