CVE-2026-35272: Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package)
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.4
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A local privilege escalation vulnerability affects the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. An unauthenticated attacker with local logon access to the host where PeopleTools runs can exploit this without any user interaction or special privileges. Successful exploitation gives the attacker full control over the PeopleTools instance, including read, write, and denial-of-service capabilities. HarborGuard is tracking this advisory and will make a patched-image rebuild available as soon as Oracle publishes a fix.
HarborGuard Coverage
Detection for CVE-2026-35272 is available across every HarborGuard environment. The CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images derived from affected PeopleTools base layers.
AvailableTriage is available using the CVSS v3.1 base score of 8.4 (HIGH), weighted against each customer environment's compliance policy to determine urgency and routing. Findings are surfaced to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableNo fix version has been published by Oracle for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will be initiated without manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or process on the host running PeopleTools; no network path to the service is required.
- AuthenticationNot required
No account or credentials are required to attempt this exploit; any process with local logon access to the infrastructure is sufficient.
- Victim interactionNot required
No user action is needed; the attacker can exploit the vulnerability entirely on their own without involving another party.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental prerequisites.
Blast Radius
- Reads all data accessible to the PeopleTools process, including configuration files, credentials, and application data.
- Modifies or destroys any files and database records the PeopleTools process can write, including deployment artifacts and application configuration.
- Crashes or fully disables the PeopleTools service, making dependent business processes unavailable.
- Achieves full takeover of the PeopleTools instance, which may serve as a pivot point into connected Oracle database backends or adjacent enterprise systems.
How HarborGuard Handles This
Available on HarborGuard: images derived from affected PeopleTools 8.61 and 8.62 base layers are flagged at a HIGH (8.4) severity as soon as the CVE is matched during a scan cycle. Because Oracle has not yet published a fix, no patched-image rebuild is available at this time. HarborGuard monitors the Oracle advisory on every ingest cycle and will trigger a rebuild automatically the moment a fix version is published; customers with auto-remediation enabled will receive the rebuild, a regression test run, and a PR opened against affected workloads without manual steps. In the interim, recommended compensating controls include restricting local logon access to the host running PeopleTools to the minimum necessary accounts, applying OS-level mandatory access controls or container security profiles to limit what processes can execute in the PeopleTools environment, and isolating the host from unnecessary lateral network paths to reduce post-exploitation reach.
- Oracle Corporation / PeopleSoft Enterprise PT PeopleTools8.61 · 8.62
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H