What is CVE-2026-35273?
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Timeline
- 2026-06-11Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-12First covered in a defend.network daily briefing
- 2026-06-12Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-15CISA federal remediation deadline (BOD 22-01)
- 2026-07-23NVD record last updated
CISA Known Exploited Vulnerability
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Affected product
Oracle PeopleSoft Enterprise PeopleTools
Remediation Steps
- Apply Oracle PeopleSoft Enterprise security patch
- Review Oracle security advisories for affected version guidance
- Prioritize patching systems accessible from external networks
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of July 2026 (July 6 – 12)
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- Vulnerability Priority Report – Week 4 of June 2026 (June 22 – 28)
- Vulnerability Priority Report – Week 3 of June 2026 (June 15 – 21)
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
- Critical: Oracle PeopleSoft Zero-Day, Windows BitLocker Bypass, Gentlemen Ransomware (2026-06-12)
Browse all tracked CVEs in the defend.network CVE database →