CVE-2026-35273

Analyzed
Published: 11 Jun 2026, 02:25
Last modified:13 Jun 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
92.33% CRITICAL
92% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
Known Use
Public exploits
None found
Dark Web
Not detected

Timeline

11 Jun 2026, 02:25
Published
Vulnerability first disclosed
12 Jun 2026, 00:00
Added to CISA KEV
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
13 Jun 2026, 03:55
Last Modified
Vulnerability information updated
15 Jun 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 92.33% Percentile: 100%

Techniques & Countermeasures

  • CWE-306Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Affected Systems

  • oracle corporationpeoplesoft enterprise peopletools

    8.61 | 8.62

  • UnknownPeopleSoft Enterprise PeopleTools

    8.61 | 8.62

References (2)