CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Severity
critical
Actively exploited
actively exploited (KEV)
99.8 %
Critical — model predicts very high exploitation likelihood in the next 30 days.
Published
2026-06-11 04:16 UTC
CWE-306

Weakness classes (CWE)

  • CWE-306Base

    Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 09:10 UTC· nvd@nist.gov
    • Translation: Title: PeopleSoft Enterprise PeopleTools de Oracle Corporation, Description: Vulnerabilidad en el producto PeopleSoft Enterprise PeopleTools de Oracle PeopleSoft (componente: Updates Environment Management). Las versiones compatibles afectadas son 8.61 y 8.62. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer PeopleSoft Enterprise PeopleTools. Los ataques exitosos de esta vulnerabilidad pueden resultar en la toma de control de PeopleSoft Enterprise PeopleTools. Puntuación base CVSS 3.1 de 9.8 (impactos en la Confidencialidad, Integridad y Disponibilidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
  2. Initial Analysis2026-06-12 19:15 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:* *cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273 Types: Third Party Advisory, US Government Resource
    • Reference Type: Oracle: https://www.oracle.com/security-alerts/alert-cve-2026-35273.html Types: Vendor Advisory
  3. CVE CISA KEV Update2026-06-12 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-06-12
    • Due Date: 2026-06-12
    • Required Action: 2026-06-12
    • Vulnerability Name: 2026-06-12
  4. CVE Modified2026-06-12 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Source: CISA_KEV

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Linked advisories