Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-24 · updated: 2026-09-24 · tags: [cve, oracle, peoplesoft, rce, enterprise-software] · confidence: high · severity: critical · affected_sectors: [government, education, healthcare, financial-services, technology] · au_impact: true

CVE-2026-35273

Summary

An unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, the middleware layer behind PeopleSoft HR, finance, campus and employee self-service deployments. NVD records it at CVSS 3.1 9.8 (Critical)AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — affecting PeopleTools 8.61 and 8.62, and Oracle frames successful exploitation as takeover of the product itself.

Details

The affected component is Updates Environment Management. Oracle's advisory language — "easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools" — describes a pre-authentication, network-reachable path with no user interaction, which is the profile typically associated with widespread scanning once a working exploit circulates.

The CVE is referenced in the September 2026 ShinyHunters claim against the FBI: the group told The Register it used "a new Oracle PeopleSoft zero-day" to gain remote code execution and deface the Bureau's jobs site. The distinction matters and should be held firmly — CVE-2026-35273 is the June 2026 PeopleSoft flaw the same group weaponised to breach enterprise networks, not the flaw claimed in the FBI incident, and no pre-authenticated PeopleSoft RCE zero-day has been publicly detailed in connection with that claim.

Attribute Detail
CVE CVE-2026-35273
CVSS 9.8 (NVD, CVSS 3.1) — Critical
Vendor / product Oracle — PeopleSoft Enterprise PeopleTools, Updates Environment Management, 8.61 / 8.62
Reported 11 June 2026 (NVD publication)

Australian Significance

PeopleSoft is widely deployed across Australian universities, state health services and government shared-services functions for HR, payroll, finance and student administration — implementations that are frequently internet-reachable through self-service portals and integration endpoints. Because the flaw is pre-authentication and requires no user interaction, exposure is determined by whether the PeopleTools interface is reachable from untrusted networks, not by user behaviour; Oracle's quarterly CPU cycle is the relevant patch cadence and any instance still on 8.61 or 8.62 without the June 2026 update should be treated as exposed.

Source