CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Other sources
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35273?
The severity of CVE-2026-35273 is critical with a score of 9.8.
How do I fix CVE-2026-35273?
To fix CVE-2026-35273, upgrade Oracle PeopleSoft Enterprise PeopleTools to supported versions that are not affected, specifically versions beyond 8.62.
What versions of Oracle PeopleSoft are affected by CVE-2026-35273?
CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
Who can exploit CVE-2026-35273?
CVE-2026-35273 can be exploited by unauthenticated attackers with network access via HTTP.
What type of vulnerability is CVE-2026-35273?
CVE-2026-35273 is categorized as an easily exploitable vulnerability that allows for full compromise of the system.