← Intelligence Center

Oracle PeopleSoft PeopleTools Vulnerability Could Allow for Remote Code Execution (CVE-2026-35273)

PublishedJun 11, 2026
Updated
VendorOracle
SeverityHigh
Known ExploitedYes Known Exploited
Advisory IDINTEL-000009
CVEs
CVE-2026-35273
Products
  • PeopleSoft Enterprise PeopleTools versions 8.61, 8.62

Executive Summary

MS-ISAC Advisory 2026-059 (issued 6/11/2026): a vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools allows an attacker with network access via HTTP to completely take over the software, resulting in remote code execution and potential full system compromise without authentication or user interaction. Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.

Municipal Impact

MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities. Municipalities running internet-facing PeopleTools are particularly at risk.

SMB Impact

MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.

Recommended Actions

  1. Apply appropriate updates provided by Oracle to vulnerable systems immediately after appropriate testing.
  2. Restrict network access to PeopleSoft/PeopleTools components, especially from the internet.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter