LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 12, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 15, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-35273 to its Known Exploited Vulnerabilities catalog on Jun 12, 2026, with a federal patch deadline of Jun 15, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise…

PeopleSoft Enterprise PeopleTools is an enterprise application platform used for human resources, finance, and other business functions. CVE-2026-35273 is a missing authentication vulnerability that allows an unauthenticated attacker to achieve takeover of the affected system. The issue is tracked under CWE-306 and has been observed in connection with ransomware activity.

How it works

The weakness is missing authentication for a critical function. An attacker who can reach the affected component can invoke it without presenting valid credentials, resulting in full control of the PeopleSoft Enterprise PeopleTools instance.

Am I affected? How to find it in your systems

Inventory all installations of Oracle PeopleSoft Enterprise PeopleTools, including development, test, and production environments. Confirm the precise versions and configurations in use against the vendor advisory, as the vulnerability description does not list specific releases.

How to remediate

Apply the vendor-supplied update or mitigation instructions referenced in the official advisory. Follow CISA BOD 26-04 guidance for prioritizing and deploying the fix, including evaluation of internet exposure for each asset.

If you can't patch immediately

Until the vendor fix can be applied, reduce exposure by limiting network access to PeopleSoft Enterprise PeopleTools instances. Follow CISA instructions for cloud services or discontinue use if mitigations cannot be implemented.

If your data may have been exposed

Because the vulnerability permits unauthenticated takeover and has been linked to ransomware activity, assume potential compromise of any data processed by the affected PeopleSoft instance. Review available logs for indicators of access or data movement. Organizations can run a free exposure scan of their email addresses against known breach data to check for related incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · PeopleSoft Enterprise PeopleTools
WeaknessCWE-306
Added to CISA KEVJun 12, 2026
Federal patch deadlineJun 15, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities