CVE-2026-47024: PeopleSoft PeopleTools: CSRF-style data tampering flaw

MEDIUM PoC AVAILABLE
Published July 21, 2026
CISO Take

This CVE affects the Panel Processor component of Oracle PeopleSoft PeopleTools 8.62, a legacy enterprise HR/ERP platform, and allows a low-privileged network attacker who lures another user into interacting with a crafted request to gain unauthorized read, insert, update, or delete access to a subset of PeopleTools-accessible data (CVSS 3.1: 5.4, C:L/I:L/A:N, scope change). Despite carrying an ai_category tag in this pipeline, PeopleSoft PeopleTools is not an AI/ML system, has no dependents in our tracked AI/ML package ecosystem, and does not appear in the CISA KEV catalog; its EPSS score of 0.00148 indicates very low real-world exploitation probability, and no public exploit code or Nuclei template exists. For CISOs this is best routed to standard enterprise patch management rather than the AI risk register — it carries no AI/ML blast radius. Apply Oracle's July 2026 Critical Patch Update (CPUJul2026) to PeopleTools 8.62 and monitor Panel Processor logs for anomalous access following unsolicited link clicks.

Sources: NVD EPSS CISA KEV oracle.com

What is the risk?

Low urgency from an AI threat intelligence standpoint: this is a traditional enterprise web-application access-control flaw (CSRF-style, UI required) in Oracle PeopleSoft, not an AI/ML component. Exploitability is technically easy (network vector, low attack complexity, low privileges required) but is gated by the need for a victim to perform an action, which meaningfully limits real-world attack volume — consistent with the very low EPSS score (0.00148) and absence from CISA KEV. There is no AI/ML deployment, model, or pipeline exposure associated with this CVE.

How does the attack unfold?

Social engineering delivery
Attacker crafts a malicious request/link targeting the Panel Processor component and lures an authenticated PeopleTools user into clicking it.
Session abuse
The victim's browser executes the attacker's request within their authenticated session, invoking Panel Processor with the victim's privileges.
Unauthorized data access/tampering
Attacker gains unauthorized read access to a subset of PeopleTools data and can insert, update, or delete a subset of records.

How severe is it?

CVSS 3.1
5.4 / 10
EPSS
0.2%
chance of exploitation in 30 days
Higher than 11% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Moderate
Exploitation Confidence
medium
Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR Low
UI Required
S Changed
C Low
I Low
A None

What should I do?

1 step
  1. Apply Oracle's Critical Patch Update for July 2026 (CPUJul2026) to PeopleTools 8.62 per the vendor advisory. Because exploitation requires user interaction, reinforce standard anti-CSRF hygiene in custom PeopleSoft integrations (same-site cookies, token validation) and train staff handling PeopleSoft links to avoid clicking untrusted-source requests. Monitor Panel Processor access logs for anomalous insert/update/delete activity following unsolicited link clicks. No AI-specific detection or compensating control applies.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Auth Bypass Data Leakage Framework

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2026-47024?

This CVE affects the Panel Processor component of Oracle PeopleSoft PeopleTools 8.62, a legacy enterprise HR/ERP platform, and allows a low-privileged network attacker who lures another user into interacting with a crafted request to gain unauthorized read, insert, update, or delete access to a subset of PeopleTools-accessible data (CVSS 3.1: 5.4, C:L/I:L/A:N, scope change). Despite carrying an ai_category tag in this pipeline, PeopleSoft PeopleTools is not an AI/ML system, has no dependents in our tracked AI/ML package ecosystem, and does not appear in the CISA KEV catalog; its EPSS score of 0.00148 indicates very low real-world exploitation probability, and no public exploit code or Nuclei template exists. For CISOs this is best routed to standard enterprise patch management rather than the AI risk register — it carries no AI/ML blast radius. Apply Oracle's July 2026 Critical Patch Update (CPUJul2026) to PeopleTools 8.62 and monitor Panel Processor logs for anomalous access following unsolicited link clicks.

Is CVE-2026-47024 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-47024, increasing the risk of exploitation.

How to fix CVE-2026-47024?

Apply Oracle's Critical Patch Update for July 2026 (CPUJul2026) to PeopleTools 8.62 per the vendor advisory. Because exploitation requires user interaction, reinforce standard anti-CSRF hygiene in custom PeopleSoft integrations (same-site cookies, token validation) and train staff handling PeopleSoft links to avoid clicking untrusted-source requests. Monitor Panel Processor access logs for anomalous insert/update/delete activity following unsolicited link clicks. No AI-specific detection or compensating control applies.

What is the CVSS score for CVE-2026-47024?

CVE-2026-47024 has a CVSS v3.1 base score of 5.4 (MEDIUM). The EPSS exploitation probability is 0.21%.

What are the technical details?

Original Advisory

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

Exploitation Scenario

An attacker with low-privilege network access to a PeopleSoft PeopleTools 8.62 instance crafts a malicious link or embedded request targeting the Panel Processor component and lures a higher-privileged, authenticated user (e.g., via a phishing email or a compromised internal page) into clicking it. When the victim's browser executes the request within their authenticated session, the attacker's Panel Processor call runs with the victim's privileges, letting the attacker read a subset of PeopleTools-accessible data or insert/update/delete records without the victim's knowledge — a classic scope-changing CSRF-style abuse of a trusted session, unrelated to any AI/ML-specific attack path.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Timeline

Published
July 21, 2026
Last Modified
July 27, 2026
First Seen
July 21, 2026

Related Vulnerabilities