Junglewise Threat Intelligence

CVE-2026-47024: Oracle PeopleSoft Enterprise PeopleTools data manipulation in Panel Processor

CVE-2026-47024 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle PeopleTools. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise PeopleTools, a foundational platform for managing enterprise business applications, contains a security vulnerability in its Panel Processor component. A low-privileged user could exploit this flaw to gain unauthorized access to view, modify, or delete certain business data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to broader impacts across connected enterprise systems.

Technical details

A vulnerability exists in the Panel Processor component of Oracle PeopleSoft Enterprise PeopleTools version 8.62. The flaw is categorized by a CVSS score of 5.4, indicating a scope change (S:C) which often suggests Cross-Site Scripting (XSS) or a similar injection vulnerability that can impact the user's browser or session in the context of other products. An attacker with low privileges can exploit this over the network via HTTP, provided they can induce a victim to perform a specific action (user interaction). Successful exploitation allows for the unauthorized reading, updating, inserting, or deleting of a subset of data accessible through PeopleTools.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.62

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-47024 by Oracle.
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released.

References

Related threats