Junglewise Threat Intelligence

CVE-2026-35279: Oracle PeopleSoft PeopleTools auth bypass in Performance Monitor

CVE-2026-35279 · Severity: high · CVSS 8.1 · Published 2026-06-17

Technologies: Oracle PeopleSoft Enterprise PT PeopleTools. Vendors: Oracle.

Executive brief

A vulnerability exists in the Performance Monitor component of Oracle PeopleSoft PeopleTools, a platform used to manage and run PeopleSoft applications. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. A successful attack could lead to a complete takeover of the application, potentially exposing sensitive business data and disrupting operations.

Technical details

This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools. It affects versions 8.61 and 8.62. An unauthenticated attacker can exploit this over the network via HTTP, though the exploit is characterized as having high complexity. Successful exploitation allows for a complete compromise of the PeopleTools environment, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats