Junglewise Threat Intelligence

CVE-2026-35276: Oracle PeopleSoft PeopleTools authentication bypass in Application Server

CVE-2026-35276 · Severity: high · CVSS 8.1 · Published 2026-06-17

Technologies: Oracle PeopleSoft Enterprise PT PeopleTools. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise PT PeopleTools, a foundational platform for managing PeopleSoft applications, contains a vulnerability in its Application Server component. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. A successful attack could lead to a complete takeover of the application, potentially exposing sensitive business data and disrupting critical operations.

Technical details

This vulnerability is classified as a Missing Authentication for Critical Function (CWE-306) within the Application Server component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. An unauthenticated attacker can exploit this flaw via HTTP over a network. While the attack is characterized as having high complexity, a successful exploit allows for a complete compromise of the PeopleTools environment, impacting confidentiality, integrity, and availability. The vulnerability was disclosed in the June 2026 Oracle Critical Patch Update.

Affected products

  • Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle and NVD publication.

References

Related threats