CVE-2026-47049: Medium severity Oracle PeopleSoft Enterprise PeopleTools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47049?
CVE-2026-47049 has a severity rating of medium with a CVSS score of 4.9.
How do I fix CVE-2026-47049?
To address CVE-2026-47049, apply the recommended patches from Oracle for PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
What versions of Oracle PeopleSoft are affected by CVE-2026-47049?
CVE-2026-47049 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
What type of access is needed to exploit CVE-2026-47049?
Exploitation of CVE-2026-47049 requires a high privileged attacker with network access via HTTP.
What component of Oracle PeopleSoft does CVE-2026-47049 affect?
CVE-2026-47049 affects the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools.