Knox CVE Database
/
CVE-2026-35273
Critical
9.8
Ransomware use

CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

Added to the CISA KEV catalog:
June 12, 2026

Overview

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability details

Affected vendor
Oracle
Affected product
PeopleSoft Enterprise PeopleTools
Weakness type (CWE)
CWE-306

This vulnerability is classified as CWE-306, Missing Authentication for Critical Function, located in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. This component handles environment management operations for PeopleSoft's update and configuration tooling, functionality that should require authenticated, privileged access. Instead, one or more HTTP-accessible endpoints in this component fail to enforce any authentication check before performing sensitive operations, allowing requests to reach critical logic without first validating caller identity or session state.

Because the CVSS vector specifies network attack vector, low complexity, no privileges, and no user interaction, an attacker only needs HTTP reachability to the affected PeopleTools instance to exploit it. Given the high confidentiality, integrity, and availability impact, successful exploitation results in full takeover of the PeopleTools environment, likely including creation of administrative accounts, modification of environment configuration, or execution of arbitrary operations within the application server context. This makes internet-exposed PeopleSoft deployments especially attractive to opportunistic scanning and, consistent with the confirmed ransomware association, to actors chaining the access into broader compromise.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review PeopleSoft web server (PIA) and application server access logs for unauthenticated requests to Updates Environment Management endpoints, especially from unfamiliar source IPs.
  • Monitor PeopleSoft audit tables and PeopleTools security logs for unexpected account creation, permission list changes, or configuration modifications with no corresponding authenticated session.
  • Alert on anomalous HTTP methods or parameter patterns targeting PeopleTools administrative/environment-management URLs, particularly outside normal maintenance windows.
  • Correlate PeopleSoft process scheduler and integration broker logs for unusual job submissions or service calls that could indicate post-exploitation activity.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 15, 2026

Additional hardening

  • Restrict network access to PeopleSoft PeopleTools administrative and environment management interfaces to trusted internal networks or VPN, removing direct internet exposure.
  • Place a web application firewall or reverse proxy in front of PeopleSoft to block or tightly filter requests to Updates Environment Management URLs from untrusted sources.
  • Enforce network segmentation isolating PeopleSoft application and database tiers from general corporate and internet-facing networks to limit lateral movement if the interface is reached.
  • Enable enhanced PeopleSoft audit logging and forward logs to a central SIEM to shorten detection time for unauthorized configuration or account changes.

Key dates

Published (NVD)
June 11, 2026
Added to CISA KEV
June 12, 2026
Remediation deadline
June 15, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-35273 affect my FedRAMP authorization?

If Oracle PeopleSoft Enterprise PeopleTools runs inside your authorization boundary, yes. CVE-2026-35273 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of June 15, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-35273?

Knox doesn't patch your software for you — remediating Oracle PeopleSoft Enterprise PeopleTools is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-35273 isn't remediated by June 15, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting