ZeroHour

CVE-2026-35273

KEV ransomwarelarge

Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleTools

CISA: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2026-35273 is a missing-authentication flaw (CWE-306) in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools, affecting supported releases 8.61 and 8.62. An unauthenticated attacker with network access over HTTP can reach the vulnerable component with no credentials and no user interaction, and successful attacks result in full takeover of the PeopleTools environment — reported in the wild as remote code execution followed by data theft. Organizations running PeopleSoft — including universities, government agencies and large enterprises — are affected, and the ShinyHunters group has already used the flaw against unpatched universities, with Nissan disclosing an employee-data breach linked to it. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-12 with ransomware use noted, and EPSS assigns a 95.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but exploitation is confirmed in the wild, having been used as a zero-day before patching.

What to do: Apply the PeopleTools security fixes for releases 8.61 and 8.62 per Oracle's advisory instructions immediately, prioritizing internet-facing instances to meet CISA KEV/BOD 26-04 timelines; where patching is not yet possible, restrict HTTP access to the PeopleSoft tier from untrusted networks. Review web and application logs on 8.61/8.62 environments for signs of unauthenticated access to the Updates Environment Management component, given confirmed ShinyHunters exploitation and ransomware use. Organizations unable to mitigate internet exposure should follow BOD 26-04 guidance for cloud services or consider discontinuing use of the exposed product.

Affected
Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component)8.61, 8.62
Estimated exposure
largetens of thousands of PeopleTools environments across thousands of organizations (only a subset internet-exposed); exact counts unknown — PeopleSoft is broadly deployed by universities, government agencies and large enterprises, which typically run several PeopleTools environments each, but no authoritative install-base or internet-exposure scan figures were provided in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle PeopleSoft Enterprise PeopleTools
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Due date
Ransomware use
Known
Vendors
oracle
Products
peoplesoft enterprise peopletools
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news