HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-35273Published Modified CNA oracle

CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unauthenticated remote takeover vulnerability affects the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. The flaw is reachable over HTTP from any network without credentials or victim interaction, placing it at the highest exploitability tier. Successful exploitation gives an attacker full control of the PeopleTools instance, including complete read, write, and availability impact. HarborGuard is tracking the advisory for patch availability, as no fix versions have been published yet.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from Oracle and upstream vulnerability feeds within minutes of publication and matched against customer images, including custom-built images that bundle PeopleSoft Enterprise PeopleTools 8.61 or 8.62. Any image in a customer registry or CI pipeline containing an affected version surfaces in findings immediately.

Available
Triage

HarborGuard scores this CVE at 9.8 Critical using the CVSS v3.1 base score and is capable of weighting findings further against each environment's compliance policy to reflect business context. Routed findings are directed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

No fix version has been published by Oracle for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment upstream publishes a fix. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will trigger automatically once a fix version is confirmed.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the PeopleTools HTTP service over a network; no physical or local access is required.

  • AuthenticationNot required

    No credentials of any kind are needed; the vulnerable endpoint is exposed to unauthenticated requests.

  • Victim interactionNot required

    The attack is fully server-side and completes without any action from a logged-in user or administrator.

  • Attack complexityDetail

    Exploit complexity is low, meaning the attack is reliable and requires no special race conditions, memory layout knowledge, or other environmental preconditions.

Blast Radius

  • A successful attacker reads all data accessible to the PeopleTools application, including HR records, credentials, and session tokens stored within the system.
  • The attacker can modify or delete persisted data, including configuration, user accounts, and business-critical records managed by PeopleTools.
  • The attacker can crash or permanently disable the PeopleTools service, causing a full denial of availability for dependent business processes.
  • The combination of full confidentiality, integrity, and availability compromise constitutes a complete takeover of the affected PeopleTools instance.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35273, HarborGuard monitors the advisory on every ingest cycle and will surface a patched-image rebuild the moment a fix version is released upstream. In the interim, customers should consider network-policy isolation to restrict HTTP access to the Updates Environment Management component to known, trusted source CIDRs only; egress filtering to limit what the PeopleTools host can reach in the event of compromise; and feature-flag or access-control gating to reduce the exposed attack surface. Where compliance policy permits, auto-remediation will trigger a rebuild, regression test run, and PR against affected workloads immediately upon upstream fix publication, with a median time from CVE publication to merged patch PR of around 90 minutes for critical-severity issues in environments with auto-remediation enabled.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / PeopleSoft Enterprise PeopleTools
    8.61 · 8.62
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References