Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
The Updates Environment Management component of PeopleSoft Enterprise PeopleTools exposes a critical administrative function over HTTP without requiring any authentication. An attacker who can reach the interface sends crafted requests straight to the unprotected endpoint, with no credentials, session token or prior foothold, and achieves remote code execution and full takeover of the instance. The missing trust boundary means the application processes unauthenticated requests as though they were authorized. Two PeopleTools releases are affected, and the flaw is confirmed exploited in the wild.
The Updates Environment Management component of PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 exposes a critical administrative function over HTTP without requiring any authentication (CWE-306). This weakness class represents a missing trust boundary: the application accepts and processes inbound requests from unauthenticated network actors as if they were authorized. Because the function is classified as critical, the consequence of bypassing the authentication gate is not limited to information disclosure but extends to full system manipulation, consistent with the high confidentiality, integrity, and availability impact ratings.
An attacker with network access to the PeopleSoft HTTP interface sends crafted requests directly to the unprotected Updates Environment Management endpoint. No credentials, session token, or prior foothold are required. Successful exploitation results in remote code execution and full takeover of the PeopleSoft Enterprise PeopleTools instance. This vulnerability is confirmed as exploited in the wild and has been associated with ransomware activity, making rapid remediation a priority. The only preconditions are that the affected component is network-reachable and that the instance runs an unpatched version 8.61 or 8.62.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Oracle PeopleSoft Enterprise PeopleTools runs inside your authorization boundary, yes, CVE-2026-35273 affects your FedRAMP authorization. CISA's Known Exploited Vulnerabilities catalog lists this vulnerability with a remediation deadline of June 15, 2026. An unpatched Known Exploited Vulnerability inside your boundary is an assessor finding: one you must remediate or formally document a mitigation for before your assessor or sponsoring agency raises it.
Remediating Oracle PeopleSoft Enterprise PeopleTools is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that help you document the fix for your next assessment. The patch is yours to apply; maintaining a compliant posture while you apply it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-35273. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you time to act before a finding becomes a formal problem.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If you don't patch CVE-2026-35273 by June 15, 2026, it becomes a Plan of Action and Milestones (POA&M) item. As your POA&M list grows, routine continuous-monitoring reviews turn into tough agency conversations. Hitting the deadline protects both your authorization and your standing with the sponsoring agency.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









