Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-35273 — CVE-2026-35273 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2026-35273
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed Teaming
GitHub0xblackash/cve-2026-35273

CVE-2026-35273

CVE-2026-35273

View Repository
232 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2026-35273 - Oracle PeopleSoft PeopleTools Unauthenticated Remote Code Execution

ChatGPT Image Jun 12, 2026, 10_20_02 AM

Severity CVSS Vendor Product CWE


⚠️ Critical Unauthenticated RCE in Oracle PeopleSoft PeopleTools

A vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools that allows remote attackers to compromise vulnerable systems without authentication.


📖 Overview

CVE-2026-35273 is a critical vulnerability affecting the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools.

The vulnerability can be exploited remotely over the network without authentication, potentially resulting in:

  • Remote Code Execution (RCE)
  • Complete system compromise
  • Unauthorized access to enterprise data
  • Configuration manipulation
  • Service disruption

🎯 Vulnerability Information


🔥 Affected Versions

ProductVersion
Oracle PeopleTools8.61
Oracle PeopleTools8.62

⚡ Attack Characteristics

root@kitploit:~
Attack Vector      : Network
Attack Complexity  : Low
Privileges Required: None
User Interaction   : None
Scope              : Unchanged
Confidentiality    : High
Integrity          : High
Availability       : High

📊 CVSS Vector

root@kitploit:~
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

🏹 Potential Impact

Successful exploitation may allow attackers to:

  • Execute arbitrary commands
  • Deploy web shells
  • Access sensitive enterprise information
  • Modify PeopleSoft configurations
  • Create privileged administrative accounts
  • Move laterally across the environment
  • Cause service outages

📸 Demo

CVE-2026-35273

🔍 Detection Opportunities

Security teams should monitor for:

Suspicious HTTP Requests

root@kitploit:~
Unexpected requests targeting:
- Environment Management endpoints
- Update services
- Administrative interfaces

Process Monitoring

root@kitploit:~
cmd.exe
powershell.exe
bash
sh
python
perl

File Monitoring

root@kitploit:~
.jsp
.php
.asp
.aspx
.war
.jar

Network Indicators

root@kitploit:~
Unexpected outbound connections
Reverse shell behavior
Beaconing activity

🛡️ Mitigation

Immediate Actions

1. Apply Oracle Security Updates

Update PeopleTools to Oracle's fixed release.

2. Restrict Access

root@kitploit:~
✓ Limit access to management interfaces
✓ Restrict trusted administrator IPs
✓ Use VPN access where possible

3. Enable Monitoring

root@kitploit:~
✓ Web server logs
✓ Process creation logs
✓ Authentication logs
✓ Network telemetry

4. Conduct Threat Hunting

Search for:

root@kitploit:~
New administrator accounts
Unknown scheduled tasks
Suspicious web files
Unusual outbound traffic

🔬 Technical Summary


📚 References

  • Oracle Security Alert
  • NIST NVD Entry
  • Oracle Critical Patch Advisory

⚠️ Disclaimer

This repository is provided for:

  • Security awareness
  • Defensive research
  • Detection engineering
  • Incident response preparation

It is not intended to facilitate unauthorized access or exploitation of systems.


🔴 Critical Severity - CVSS 9.8

Patch Immediately

Oracle PeopleSoft PeopleTools — CVE-2026-35273

Download Tool
PropertyValue
CVECVE-2026-35273
VendorOracle
ProductPeopleSoft Enterprise PeopleTools
SeverityCritical
CVSS v3.19.8
CWECWE-306
Attack VectorNetwork
AuthenticationNot Required
User InteractionNone
ImpactRemote Code Execution
CategoryDetails
Vulnerability TypeMissing Authentication
CWECWE-306
ExposureRemote
ExploitabilityHigh
Authentication RequiredNo
Privileges RequiredNo
User InteractionNo