
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47026 is a vulnerability in the OpenSearch Dashboards component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. The flaw allows an unauthenticated remote attacker with network access via HTTP to compromise the product, though successful exploitation requires human interaction from a victim user. It was disclosed on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update (CPU). The vulnerability carries a CVSS v3.1 base score of 7.4 (High) (Oracle Advisory).
The vulnerability is classified as a cross-site request forgery (CSRF) or similar client-side attack (consistent with CWE patterns involving scope change and user interaction requirements) within the OpenSearch Dashboards component of PeopleSoft Enterprise PeopleTools. An unauthenticated attacker can craft a malicious HTTP request or link that, when interacted with by a legitimate authenticated user, causes the application to perform unauthorized actions on behalf of that user. The changed scope indicator in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially affecting other PeopleSoft products or data accessible through OpenSearch Dashboards. No public proof-of-concept code has been identified (Oracle Advisory).
Successful exploitation results in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools data accessible through the OpenSearch Dashboards component, representing a high confidentiality impact. There is no integrity or availability impact associated with this vulnerability. The scope change noted in the CVSS scoring indicates that data from additional products beyond PeopleTools itself may be exposed, increasing the potential blast radius of a successful attack (Oracle Advisory).
Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update; organizations should apply the relevant PeopleSoft patch immediately. As interim mitigations, network access controls should be implemented to restrict HTTP access to OpenSearch Dashboards to only authorized internal users and networks. Web application firewalls (WAF) can be configured to detect and block suspicious cross-site request patterns targeting PeopleTools endpoints. Users should be educated to avoid clicking untrusted links related to PeopleTools applications (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."