Junglewise Threat Intelligence

CVE-2026-47048: Oracle PeopleSoft Enterprise PeopleTools security bypass in Security component

CVE-2026-47048 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise PeopleTools, a foundational suite for managing enterprise applications, contains a security vulnerability in its Security component. A low-privileged user could potentially trick another user into performing actions that allow the attacker to view, modify, or delete sensitive business data. While the direct impact is within the PeopleTools environment, the breach could potentially affect other integrated business systems.

Technical details

This vulnerability exists in the Security component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. It is classified as a low-complexity attack requiring low-level privileges and network access via HTTP. The exploit requires human interaction (UI:R) and results in a scope change (S:C), suggesting a cross-site scripting (XSS) or similar injection-based flaw that allows an attacker to execute actions in the context of another user. Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of PeopleTools data. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats