Knox CVE Database
/
CVE-2026-35273
Critical
9.8
Ransomware use

CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

Added to the CISA KEV catalog:
June 12, 2026

Overview

The Updates Environment Management component of PeopleSoft Enterprise PeopleTools exposes a critical administrative function over HTTP without requiring any authentication. An attacker who can reach the interface sends crafted requests straight to the unprotected endpoint, with no credentials, session token or prior foothold, and achieves remote code execution and full takeover of the instance. The missing trust boundary means the application processes unauthenticated requests as though they were authorized. Two PeopleTools releases are affected, and the flaw is confirmed exploited in the wild.

Vulnerability details

Affected vendor
Oracle
Affected product
PeopleSoft Enterprise PeopleTools
Weakness type (CWE)
CWE-306

The Updates Environment Management component of PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 exposes a critical administrative function over HTTP without requiring any authentication (CWE-306). This weakness class represents a missing trust boundary: the application accepts and processes inbound requests from unauthenticated network actors as if they were authorized. Because the function is classified as critical, the consequence of bypassing the authentication gate is not limited to information disclosure but extends to full system manipulation, consistent with the high confidentiality, integrity, and availability impact ratings.


An attacker with network access to the PeopleSoft HTTP interface sends crafted requests directly to the unprotected Updates Environment Management endpoint. No credentials, session token, or prior foothold are required. Successful exploitation results in remote code execution and full takeover of the PeopleSoft Enterprise PeopleTools instance. This vulnerability is confirmed as exploited in the wild and has been associated with ransomware activity, making rapid remediation a priority. The only preconditions are that the affected component is network-reachable and that the instance runs an unpatched version 8.61 or 8.62.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review PeopleSoft web server access logs for requests to Updates Environment Management paths that carry no associated authenticated session cookie or token; successful responses (HTTP 200) to such requests on unpatched instances indicate exploitation.
  • Monitor host-based process telemetry on PeopleSoft application servers for unexpected child processes or OS-level command execution spawned from the PeopleSoft application process, which would indicate post-exploitation code execution following unauthenticated access.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 15, 2026

Additional hardening

  • Restrict network access to PeopleSoft application ports at the perimeter firewall, permitting only known, trusted IP ranges to reach the service.
  • Disable or isolate the Updates Environment Management component if it is not operationally required, reducing the exposed attack surface until patching is complete.
  • Place PeopleSoft instances behind a reverse proxy or WAF configured to require authentication before forwarding requests to administrative management endpoints.
  • Conduct forensic triage per CISA guidance on any unpatched instance that was internet-reachable, given confirmed ransomware exploitation in the wild.

Key dates

Published (NVD)
June 11, 2026
Added to CISA KEV
June 12, 2026
Remediation deadline
June 15, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-35273 affect my FedRAMP authorization?

If Oracle PeopleSoft Enterprise PeopleTools runs inside your authorization boundary, yes, CVE-2026-35273 affects your FedRAMP authorization. CISA's Known Exploited Vulnerabilities catalog lists this vulnerability with a remediation deadline of June 15, 2026. An unpatched Known Exploited Vulnerability inside your boundary is an assessor finding: one you must remediate or formally document a mitigation for before your assessor or sponsoring agency raises it.

How does Knox help me handle CVE-2026-35273?

Remediating Oracle PeopleSoft Enterprise PeopleTools is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that help you document the fix for your next assessment. The patch is yours to apply; maintaining a compliant posture while you apply it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-35273. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-35273 isn't remediated by June 15, 2026?

If you don't patch CVE-2026-35273 by June 15, 2026, it becomes a Plan of Action and Milestones (POA&M) item. As your POA&M list grows, routine continuous-monitoring reviews turn into tough agency conversations. Hitting the deadline protects both your authorization and your standing with the sponsoring agency.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting