← Vulnerability feed

Vulnerability record · CVE-2026-35273 · published 11 June 2026

CVE-2026-35273: Oracle PeopleSoft PeopleTools missing authentication allows takeover

Oracle · Peoplesoft Enterprise Peopletools

Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critical function, allowing an unauthenticated network attacker to compromise the product. Successful exploitation results in full takeover of the affected PeopleSoft Enterprise PeopleTools instance.

9.8 CVSS 3.1 Critical CISA KEV since 12 Jun 2026 Known ransomware use EPSS 9.4% · top 4.7% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
9.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
23 Jul 2026Last modified by NVD

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable full takeover with a 9.8 CVSS score, active KEV listing with ransomware use, and near-certain EPSS exploitation probability.

What it is

Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critical function, allowing an unauthenticated network attacker to compromise the product. Successful exploitation results in full takeover of the affected PeopleSoft Enterprise PeopleTools instance.

Impact

An attacker gains complete control of the affected PeopleSoft Enterprise PeopleTools system, with high confidentiality, integrity and availability impact, including potential data theft, tampering and service disruption.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed PeopleSoft Enterprise PeopleTools 8.61 or 8.62 endpoint running the Updates Environment Management component is in scope.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-06-12 with known ransomware campaign use, and EPSS gives a 30-day exploitation probability of 0.95473 (99.867th percentile), indicating active exploitation.

What to do

  • Apply the Oracle security alert patch for CVE-2026-35273 to PeopleSoft Enterprise PeopleTools 8.61 and 8.62 immediately, per CISA's 2026-06-15 due date.
  • If patching is not immediately possible, restrict network access to the Updates Environment Management component and remove internet exposure of affected PeopleSoft endpoints.
  • Follow CISA BOD 26-04 guidance for cloud-hosted instances, or discontinue use of the product where mitigations are unavailable.
  • Assume compromise on any exposed, unpatched instance and perform forensic triage per CISA requirements before returning it to service.

Detection

  • Review HTTP access logs for unauthenticated requests to PeopleSoft Enterprise PeopleTools Updates Environment Management endpoints, especially from unfamiliar source IPs.
  • Hunt for post-exploitation activity on PeopleSoft hosts such as new administrative accounts, unexpected configuration changes, or outbound connections to unknown hosts.
  • Correlate endpoint and network telemetry for indicators of ransomware staging or lateral movement on systems hosting PeopleSoft Enterprise PeopleTools.
  • Audit PeopleSoft application and web server logs for anomalous administrative actions occurring outside normal change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-35273 to the Known Exploited Vulnerabilities catalog on 12 June 2026 as "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 15 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-35273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%10.0CVE-2008-0345Oracle application server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 2.6%10.0CVE-2008-0346Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact …EPSS 2.7%10.0CVE-2008-0347Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Ap…EPSS 2.7%10.0CVE-2008-0348Oracle application server vulnerabilityMultiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and …EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2026-35273), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.