CVE-2026-47051
Oracle Peoplesoft Enterprise Peopletools vulnerability analysis and mitigation

Overview

CVE-2026-47051 is an authorization bypass vulnerability in the Security component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. Disclosed as part of Oracle's July 2026 Critical Patch Update (CPU), it allows a low-privileged attacker with network access via HTTP to perform unauthorized data manipulation and read operations, with a scope change that may impact additional connected products. The vulnerability has a CVSS v3.1 base score of 5.4 (Medium) (Oracle CPU July 2026).

Technical details

The vulnerability resides in the Security component of PeopleSoft Enterprise PeopleTools and is classified as an authorization bypass (CWE not explicitly specified by Oracle, but consistent with improper access control). Exploitation requires a low-privileged attacker with network access via HTTP and human interaction from a third party (e.g., a social engineering component), making it a client-side attack vector. The scope change indicates that a successful attack on PeopleTools can significantly impact other Oracle products integrated with the platform (Oracle CPU July 2026).

Impact

Successful exploitation allows an attacker to perform unauthorized update, insert, or delete operations on a subset of PeopleSoft Enterprise PeopleTools accessible data, as well as read a subset of that data. There is no availability impact, but the confidentiality and integrity of PeopleTools data — and potentially connected Oracle products due to scope change — are at risk. This could expose sensitive enterprise data such as HR, financial, or student records managed through PeopleSoft (Oracle CPU July 2026).

Exploitation steps

  1. Reconnaissance: Identify internet-facing PeopleSoft Enterprise PeopleTools instances running versions 8.61 or 8.62 using network scanning tools or public search engines (e.g., Shodan, Censys).
  2. Obtain low-privileged credentials: Acquire valid low-privileged user credentials for the PeopleSoft environment through phishing, credential stuffing, or other means.
  3. Craft malicious HTTP request: Prepare a specially crafted HTTP request targeting the Security component of PeopleTools that exploits the authorization bypass flaw.
  4. Social engineering for human interaction: Induce a legitimate user (other than the attacker) to interact with the malicious content or link — for example, by clicking a crafted URL — to satisfy the required human interaction precondition.
  5. Achieve unauthorized data access/manipulation: Upon successful exploitation, perform unauthorized read, insert, update, or delete operations on PeopleTools-accessible data, potentially pivoting to impact other integrated Oracle products (Oracle CPU July 2026).

Indicators of compromise

  • Network: Unusual or unexpected HTTP requests to PeopleSoft PeopleTools Security component endpoints from low-privileged user accounts; anomalous outbound connections from PeopleSoft application servers.
  • Logs: PeopleSoft application logs showing unauthorized data modification or access attempts by low-privileged accounts; repeated failed or unexpected authorization checks in Security component logs.
  • Application: Unexpected changes to PeopleSoft data records (inserts, updates, or deletes) not correlated with normal business activity; access to data subsets by accounts that should not have such permissions.

Mitigation and workarounds

Oracle has released a patch for CVE-2026-47051 as part of the July 2026 Critical Patch Update, applicable to PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Oracle strongly recommends applying the CPU patches as soon as possible. As a temporary measure, organizations can restrict network access to PeopleSoft PeopleTools to authorized personnel only, implement additional access controls, and educate users about social engineering risks that could satisfy the human interaction requirement for exploitation (Oracle CPU July 2026).

Additional resources


SourceThis report was generated using AI

Related Oracle Peoplesoft Enterprise Peopletools vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47026HIGH7.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-60152MEDIUM5.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-47051MEDIUM5.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-47048MEDIUM5.4
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026
CVE-2026-47049MEDIUM4.9
  • Oracle Peoplesoft Enterprise Peopletools logoOracle Peoplesoft Enterprise Peopletools
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management