PatchSiren cyber security CVE debrief
CVE-2026-47017 Oracle Corporation CVE debrief
A vulnerability was discovered in PeopleSoft Enterprise PeopleTools of Oracle PeopleSoft, specifically in the Process Scheduler component. The affected versions are 8.61 and 8.62. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from another person and can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data, as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise PeopleTools
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Organizations using PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 should prioritize patching this vulnerability. The vulnerability's high CVSS score of 8.7 indicates a significant risk, with potential impacts on confidentiality and integrity.
Technical summary
The vulnerability in PeopleSoft Enterprise PeopleTools has a CVSS 3.1 Base Score of 8.7, indicating a high severity. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N. This vulnerability can be exploited over the network with low privileges and requires user interaction. Successful attacks can lead to significant impacts on data integrity and confidentiality. The affected versions of PeopleSoft Enterprise PeopleTools are 8.61 and 8.62, which are components of Oracle PeopleSoft. The vulnerability is located in the Process Scheduler component.
Defensive priority
High priority should be given to patching this vulnerability due to its high CVSS score and potential impact on data security.
Recommended defensive actions
- Apply the patches provided by Oracle for PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
- Implement network access controls to limit access to PeopleSoft Enterprise PeopleTools.
- Monitor for suspicious activity and implement compensating controls if patching is not immediately feasible.
- Educate users about the risks associated with this vulnerability and the importance of human interaction in successful attacks.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-21T22:17:07.337Z and was last modified on 2026-07-27T19:36:34.077Z. The NVD entry is currently Analyzed. The vulnerability affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The CVSS score indicates high severity, and the vulnerability requires human interaction for successful exploitation.
Official resources
-
CVE-2026-47017 CVE record
CVE.org
-
CVE-2026-47017 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:07.337Z and has not been modified since then. The NVD entry is currently Analyzed.