THREAT OPS › CVEs › CVE-2026-35273
CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Vulnerability details
- Affected products PeopleSoft Enterprise PeopleTools
- KEV remediation due2026-06-15
Related reporting
- CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RATsocradar_blog
- Exploits and vulnerabilities in Q2 2026securelist
- What’s New in Rapid7 Products and Services: Q2 2026 in Reviewrapid7
- [CISA KEV] CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerabilitycisa_kev
- ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploitmandiant_gti
- June 2026 CVE Landscaperecordedfuture
- 15th June – Threat Intelligence Reportcheckpoint_research