Junglewise Threat Intelligence

CVE-2026-35278: Oracle PeopleSoft PeopleTools auth bypass in Performance Monitor

CVE-2026-35278 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle PeopleSoft Enterprise PT PeopleTools. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle PeopleSoft's Performance Monitor, a tool used to track the health and performance of PeopleSoft applications. An unauthorized person can exploit this flaw over the network without needing a username or password. A successful attack could allow a complete takeover of the system, potentially leading to the theft of sensitive data or a total disruption of business operations.

Technical details

A vulnerability in the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools (versions 8.61 and 8.62) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. By bypassing authentication requirements, an attacker can gain full control over the PeopleTools environment, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8, reflecting its high impact and low complexity. Users are advised to refer to the Oracle June 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published the security alert.

References

Related threats