CVE-2026-47026
Oracle Peoplesoft Enterprise Peopletools vulnerability analysis and mitigation

Overview

CVE-2026-47026 is a vulnerability in the OpenSearch Dashboards component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. The flaw allows an unauthenticated remote attacker with network access via HTTP to compromise the product, though successful exploitation requires human interaction from a victim user. It was disclosed on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update (CPU). The vulnerability carries a CVSS v3.1 base score of 7.4 (High) (Oracle Advisory).

Technical details

The vulnerability is classified as a cross-site request forgery (CSRF) or similar client-side attack (consistent with CWE patterns involving scope change and user interaction requirements) within the OpenSearch Dashboards component of PeopleSoft Enterprise PeopleTools. An unauthenticated attacker can craft a malicious HTTP request or link that, when interacted with by a legitimate authenticated user, causes the application to perform unauthorized actions on behalf of that user. The changed scope indicator in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially affecting other PeopleSoft products or data accessible through OpenSearch Dashboards. No public proof-of-concept code has been identified (Oracle Advisory).

Impact

Successful exploitation results in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools data accessible through the OpenSearch Dashboards component, representing a high confidentiality impact. There is no integrity or availability impact associated with this vulnerability. The scope change noted in the CVSS scoring indicates that data from additional products beyond PeopleTools itself may be exposed, increasing the potential blast radius of a successful attack (Oracle Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible PeopleSoft Enterprise PeopleTools instances running versions 8.61 or 8.62 with OpenSearch Dashboards enabled, using tools such as Shodan or internal network scanning.
  2. Craft malicious payload: Construct a malicious HTTP request or URL targeting the OpenSearch Dashboards component that, when triggered by an authenticated user's browser session, performs an unauthorized action (e.g., data retrieval or cross-site request).
  3. Deliver payload to victim: Deliver the crafted link or page to a legitimate PeopleTools user via phishing email, social engineering, or embedding in a web page the victim is likely to visit.
  4. Victim interaction triggers exploit: When the authenticated victim clicks the link or visits the malicious page, their browser sends the crafted request to the PeopleTools OpenSearch Dashboards endpoint, leveraging the victim's active session.
  5. Data exfiltration: The attacker receives unauthorized access to critical PeopleSoft data accessible through OpenSearch Dashboards, potentially including data from additional integrated products due to the scope change (Oracle Advisory).

Indicators of compromise

  • Network: Unusual or unexpected HTTP requests to OpenSearch Dashboards endpoints originating from external or untrusted IP addresses; cross-origin requests to PeopleTools OpenSearch Dashboards from unexpected referrer domains.
  • Logs: PeopleSoft application or web server access logs showing requests to OpenSearch Dashboards endpoints with anomalous referrer headers or from unexpected source IPs; repeated access to sensitive data endpoints shortly after a user interaction event.
  • Application: Unexpected data access or export activity within OpenSearch Dashboards attributed to legitimate user accounts at unusual times or from unusual locations.

Mitigation and workarounds

Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update; organizations should apply the relevant PeopleSoft patch immediately. As interim mitigations, network access controls should be implemented to restrict HTTP access to OpenSearch Dashboards to only authorized internal users and networks. Web application firewalls (WAF) can be configured to detect and block suspicious cross-site request patterns targeting PeopleTools endpoints. Users should be educated to avoid clicking untrusted links related to PeopleTools applications (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Peoplesoft Enterprise Peopletools vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47026HIGH7.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-60152MEDIUM5.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-47051MEDIUM5.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-47048MEDIUM5.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-47049MEDIUM4.9
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management