
CVE-2026-35273
A vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools that allows remote attackers to compromise vulnerable systems without authentication.
CVE-2026-35273 is a critical vulnerability affecting the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools.
The vulnerability can be exploited remotely over the network without authentication, potentially resulting in:
| Product | Version |
|---|---|
| Oracle PeopleTools | 8.61 |
| Oracle PeopleTools | 8.62 |
Attack Vector : Network
Attack Complexity : Low
Privileges Required: None
User Interaction : None
Scope : Unchanged
Confidentiality : High
Integrity : High
Availability : High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Successful exploitation may allow attackers to:
Security teams should monitor for:
Unexpected requests targeting:
- Environment Management endpoints
- Update services
- Administrative interfaces
cmd.exe
powershell.exe
bash
sh
python
perl
.jsp
.php
.asp
.aspx
.war
.jar
Unexpected outbound connections
Reverse shell behavior
Beaconing activity
Update PeopleTools to Oracle's fixed release.
✓ Limit access to management interfaces
✓ Restrict trusted administrator IPs
✓ Use VPN access where possible
✓ Web server logs
✓ Process creation logs
✓ Authentication logs
✓ Network telemetry
Search for:
New administrator accounts
Unknown scheduled tasks
Suspicious web files
Unusual outbound traffic
This repository is provided for:
It is not intended to facilitate unauthorized access or exploitation of systems.
Oracle PeopleSoft PeopleTools — CVE-2026-35273
| Property | Value |
|---|
| CVE | CVE-2026-35273 |
| Vendor | Oracle |
| Product | PeopleSoft Enterprise PeopleTools |
| Severity | Critical |
| CVSS v3.1 | 9.8 |
| CWE | CWE-306 |
| Attack Vector | Network |
| Authentication | Not Required |
| User Interaction | None |
| Impact | Remote Code Execution |
| Category | Details |
|---|
| Vulnerability Type | Missing Authentication |
| CWE | CWE-306 |
| Exposure | Remote |
| Exploitability | High |
| Authentication Required | No |
| Privileges Required | No |
| User Interaction | No |