CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise…
How it works
The weakness is missing authentication for a critical function. An attacker who can reach the affected component can invoke it without presenting valid credentials, resulting in full control of the PeopleSoft Enterprise PeopleTools instance.
- No prior authentication or session is required.
- The attack path targets functionality that should be restricted to authenticated administrators or processes.
- Successful exploitation grants the attacker the same level of access as a legitimate high-privileged user.
Am I affected? How to find it in your systems
Inventory all installations of Oracle PeopleSoft Enterprise PeopleTools, including development, test, and production environments. Confirm the precise versions and configurations in use against the vendor advisory, as the vulnerability description does not list specific releases.
- Search for running PeopleSoft application servers, process schedulers, and web components that expose administrative or integration endpoints.
- Review network-accessible services and any externally reachable interfaces.
- Examine authentication and access-control settings for critical functions to identify gaps that match the CWE-306 pattern.
- Monitor logs for unexpected unauthenticated requests to administrative or sensitive endpoints; correlate with any anomalous process creation or configuration changes.
How to remediate
Apply the vendor-supplied update or mitigation instructions referenced in the official advisory. Follow CISA BOD 26-04 guidance for prioritizing and deploying the fix, including evaluation of internet exposure for each asset.
- Verify that the update addresses the missing authentication condition before declaring systems remediated.
- Re-test authentication requirements on all critical functions after the change.
- Document completion to satisfy compliance and forensics triage requirements.
If you can't patch immediately
Until the vendor fix can be applied, reduce exposure by limiting network access to PeopleSoft Enterprise PeopleTools instances. Follow CISA instructions for cloud services or discontinue use if mitigations cannot be implemented.
- Restrict inbound access to only trusted management networks or via approved jump hosts.
- Disable or tightly control any externally facing interfaces that reach the affected components.
- Increase monitoring of authentication events and administrative actions for signs of unauthorized activity.
- Evaluate each asset against BOD 26-04 requirements and apply additional controls where patching is delayed.
If your data may have been exposed
Because the vulnerability permits unauthenticated takeover and has been linked to ransomware activity, assume potential compromise of any data processed by the affected PeopleSoft instance. Review available logs for indicators of access or data movement. Organizations can run a free exposure scan of their email addresses against known breach data to check for related incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.