
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47051 is an authorization bypass vulnerability in the Security component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. Disclosed as part of Oracle's July 2026 Critical Patch Update (CPU), it allows a low-privileged attacker with network access via HTTP to perform unauthorized data manipulation and read operations, with a scope change that may impact additional connected products. The vulnerability has a CVSS v3.1 base score of 5.4 (Medium) (Oracle CPU July 2026).
The vulnerability resides in the Security component of PeopleSoft Enterprise PeopleTools and is classified as an authorization bypass (CWE not explicitly specified by Oracle, but consistent with improper access control). Exploitation requires a low-privileged attacker with network access via HTTP and human interaction from a third party (e.g., a social engineering component), making it a client-side attack vector. The scope change indicates that a successful attack on PeopleTools can significantly impact other Oracle products integrated with the platform (Oracle CPU July 2026).
Successful exploitation allows an attacker to perform unauthorized update, insert, or delete operations on a subset of PeopleSoft Enterprise PeopleTools accessible data, as well as read a subset of that data. There is no availability impact, but the confidentiality and integrity of PeopleTools data — and potentially connected Oracle products due to scope change — are at risk. This could expose sensitive enterprise data such as HR, financial, or student records managed through PeopleSoft (Oracle CPU July 2026).
Oracle has released a patch for CVE-2026-47051 as part of the July 2026 Critical Patch Update, applicable to PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Oracle strongly recommends applying the CPU patches as soon as possible. As a temporary measure, organizations can restrict network access to PeopleSoft PeopleTools to authorized personnel only, implement additional access controls, and educate users about social engineering risks that could satisfy the human interaction requirement for exploitation (Oracle CPU July 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."