PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47049 Oracle Corporation CVE debrief

A vulnerability was discovered in PeopleSoft Enterprise PeopleTools, a product of Oracle PeopleSoft. The vulnerability affects versions 8.61 and 8.62 and allows high privileged attackers with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools, potentially leading to unauthorized access to critical data. This is a medium severity vulnerability with a CVSS 3.1 Base Score of 4.9, indicating that it is easily exploitable and could result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. System administrators and security teams should be aware of this vulnerability and take necessary actions to mitigate the risk.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise PeopleTools
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

System administrators and security teams responsible for PeopleSoft Enterprise PeopleTools installations, especially those using versions 8.61 and 8.62, should be aware of this vulnerability and take necessary actions to mitigate the risk.

Technical summary

The vulnerability, CVE-2026-47049, is in the PIA Core Technology component of PeopleSoft Enterprise PeopleTools. It has a CVSS 3.1 Base Score of 4.9, indicating a medium severity level. The vulnerability is easily exploitable and allows high privileged attackers with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools, potentially leading to unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, especially in environments where high privileged access is a concern.

Recommended defensive actions

  • Apply the latest security patches provided by Oracle for PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
  • Review and restrict network access to PeopleSoft Enterprise PeopleTools to only necessary personnel.
  • Monitor PeopleSoft Enterprise PeopleTools systems for any suspicious activity.
  • Consider implementing additional security measures such as multi-factor authentication for high privileged accounts.
  • Perform a thorough review of the system to identify any potential entry points for attackers.
  • Verify that all necessary security controls are in place to prevent exploitation.
  • Keep PeopleSoft Enterprise PeopleTools software up-to-date with the latest security patches.

Evidence notes

The CVE record was published on 2026-07-21T22:17:10.570Z and was last modified on 2026-07-27T19:34:23.627Z. The NVD entry is currently Analyzed. The vulnerability details are based on the information provided by the CVE.org and NVD.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:10.570Z and has not been modified since then. The NVD entry is currently Analyzed.