Junglewise Threat Intelligence

CVE-2026-35273: Oracle PeopleSoft PeopleTools compromise in Updates Environment Management

CVE-2026-35273 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-06-11

Technologies: Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise PeopleTools, a foundational platform for managing enterprise business applications, contains a critical security flaw in its Updates Environment Management component. This vulnerability allows an unauthorized person to gain full control over the system over the internet without needing a username or password. An exploit could lead to the complete theft of sensitive business data, unauthorized modification of records, or a total shutdown of the PeopleSoft environment.

Technical details

A missing authentication vulnerability (CWE-306) exists in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The flaw is remotely exploitable via HTTP without any prior authentication or user interaction. By sending a specially crafted request to the vulnerable endpoint, an attacker can bypass security controls to perform critical administrative functions. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability, effectively allowing a full takeover of the PeopleTools environment. This vulnerability has been reported as being exploited in the wild.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.61, 8.62

Timeline

  • 2026-06-11: disclosed: Initial disclosure by Oracle
  • 2026-06-12: advisory: NVD publication date
  • 2026-06-12: exploited: Reported as exploited in the wild in advisory metadata

Related threats