FeedVulnerabilityA Vulnerability in Oracle PeopleSoft PeopleTools Could Allow...
VulnerabilityCIS Advisories
9.8CRITICAL

A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution

📅 11 June 2026 at 18:29 UTC📰 CIS AdvisoriesView original source ↗

A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow an attacker with network access via HTTP to completely takeover the software. PeopleSoft is an integrated enterprise resource planning (ERP) software suite widely used by large organizations for managing core business functions, including HR, payroll, finance, supply chain, and campus operations. Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A remote code execution vulnerability was discovered in Oracle PeopleSoft PeopleTools, allowing an attacker with network access via HTTP to take control of the software. This vulnerability has been targeted by the ShinyHunters extortion gang in ongoing data theft attacks.

⚙️Technical Details
CVEs
CVE-2026-35273
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools, versions 8.61-8.62
Attack Vectors
NETWORK
💥Impact Assessment
Severity: HIGH
🛡️Recommended Actions
1Apply appropriate updates provided by Oracle or other vendors to vulnerable systems immediately after testing.
2Establish and maintain a documented vulnerability management process for enterprise assets, including regular reviews and remediation strategies.
3Perform automated application patch management on a monthly basis to ensure software is up-to-date.
📦Affected Products
Oracle Peoplesoft Enterprise Peopletools
🔐NVD Verified DataVERIFIED
CVE-2026-35273CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
Affected Products (CPE)
Oracle Peoplesoft Enterprise Peopletools

Read the full article

This is a curated summary. The complete article is available at CIS Advisories.

Read on CIS Advisories
← Back to feed