PatchSiren cyber security CVE debrief
CVE-2026-47017 Oracle Corporation CVE debrief
A vulnerability was discovered in PeopleSoft Enterprise PeopleTools of Oracle PeopleSoft, specifically in the Process Scheduler component. The affected versions are 8.61 and 8.62. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from another person and can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise PeopleTools
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Organizations using PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 should prioritize patching this vulnerability. The vulnerability's high CVSS score of 8.7 indicates a significant risk, with potential impacts on confidentiality and integrity.
Technical summary
The vulnerability in PeopleSoft Enterprise PeopleTools has a CVSS 3.1 Base Score of 8.7, indicating a high severity. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N. This vulnerability can be exploited over the network with low privileges and requires user interaction. Successful attacks can lead to significant impacts on data integrity and confidentiality. The affected versions of PeopleSoft Enterprise PeopleTools are 8.61 and 8.62, which are components of Oracle PeopleSoft. The vulnerability is located in the Process Scheduler component.
Defensive priority
High priority should be given to patching this vulnerability due to its high CVSS score and potential impact on data security.
Recommended defensive actions
- Apply the patches provided by Oracle for PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
- Implement network access controls to limit access to PeopleSoft Enterprise PeopleTools.
- Monitor for suspicious activity and implement compensating controls if patching is not immediately feasible.
- Educate users about the risks associated with this vulnerability and the importance of human interaction in successful attacks.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-21T22:17:07.337Z and was last modified on 2026-07-27T19:36:34.077Z. The NVD entry is currently Analyzed. The vulnerability affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The CVSS score indicates high severity, and the vulnerability requires human interaction for successful exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47017 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47017
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47017 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47017
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.