Critical 9.8 CVSS vulnerability in Oracle PeopleSoft PeopleTools 8.61-8.62 allows unauthenticated takeover via HTTP. Actively exploited and KEV-listed.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| peoplesoft_enterprise_peopletools | 8.61 | 8.61 | vulnerable |
| peoplesoft_enterprise_peopletools | 8.62 | 8.62 | vulnerable |
Immediately download and apply the latest security patches provided by Oracle through the Critical Patch Update (CPU) program, specifically targeting the PeopleSoft Enterprise PeopleTools Updates Environment Management component.
Ensure all PeopleSoft Enterprise PeopleTools environments running versions 8.61 and 8.62 are updated to the most recent secure version as specified in the Oracle security advisory.
Isolate the PeopleSoft Updates Environment Management component from the public internet. Use firewalls or VPNs to restrict HTTP/HTTPS access to authorized internal IP addresses only, following the principle of least privilege.
Enable detailed logging for the PeopleTools environment and monitor for unauthorized administrative actions, unusual POST requests to management endpoints, or the creation of unexpected high-privilege user accounts.
To detect exploitation attempts of CVE-2026-35273, monitor HTTP/HTTPS logs for unauthenticated requests directed at the Updates Environment Management component. Look for anomalous traffic patterns or payloads indicative of authentication bypass (CWE-306). Security teams should deploy IDS/IPS signatures that identify unauthorized remote execution patterns within PeopleSoft. Additionally, audit system logs for suspicious process execution or modifications to environment configuration files that occur outside of scheduled maintenance windows.
Experience superior visibility and a simpler approach to cyber risk management