Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-35273

Published 2026-06-11
Updated 2 months ago
Vendor/s
Oracle
Product/s
PeopleSoft Enterprise PeopleTools
Version/s
8.61
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical 9.8 CVSS vulnerability in Oracle PeopleSoft PeopleTools 8.61-8.62 allows unauthenticated takeover via HTTP. Actively exploited and KEV-listed.

CPE

Oracle logo
Oracle
Product Version Start Version End (excl.) Status
peoplesoft_enterprise_peopletools 8.61 8.61 vulnerable
peoplesoft_enterprise_peopletools 8.62 8.62 vulnerable

Related weakness (CWE)

CWE-306

Remediation plan

1

Apply official patches

Immediately download and apply the latest security patches provided by Oracle through the Critical Patch Update (CPU) program, specifically targeting the PeopleSoft Enterprise PeopleTools Updates Environment Management component.

2

Update affected systems

Ensure all PeopleSoft Enterprise PeopleTools environments running versions 8.61 and 8.62 are updated to the most recent secure version as specified in the Oracle security advisory.

3

Restrict access

Isolate the PeopleSoft Updates Environment Management component from the public internet. Use firewalls or VPNs to restrict HTTP/HTTPS access to authorized internal IP addresses only, following the principle of least privilege.

4

Monitor for exploitation

Enable detailed logging for the PeopleTools environment and monitor for unauthorized administrative actions, unusual POST requests to management endpoints, or the creation of unexpected high-privilege user accounts.

Detection Guidance

To detect exploitation attempts of CVE-2026-35273, monitor HTTP/HTTPS logs for unauthenticated requests directed at the Updates Environment Management component. Look for anomalous traffic patterns or payloads indicative of authentication bypass (CWE-306). Security teams should deploy IDS/IPS signatures that identify unauthorized remote execution patterns within PeopleSoft. Additionally, audit system logs for suspicious process execution or modifications to environment configuration files that occur outside of scheduled maintenance windows.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management