HIGH 8.7

CVE-2026-35271: Oracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)

CVE-2026-35271 is a network-accessible vulnerability in Oracle PeopleSoft Enterprise PT PeopleTools (versions 8.61 and 8.62) that allows an unauthenticated attacker to read, modify, or delete sensitive data without authentication. The vulnerability resides in the WebLogic component and is considered difficult to exploit, but successful attacks can compromise both PeopleSoft data and potentially impact other connected systems. The flaw carries a CVSS score of 8.7 (High severity) due to its potential for unauthorized access to critical information.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.7 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses (CWE)
CWE-284
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-24

NVD description (verbatim)

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This vulnerability in PeopleSoft Enterprise PT PeopleTools is rooted in improper access controls (CWE-284) within the WebLogic component. The attack vector is network-based over HTTP, requires no authentication, and does not depend on user interaction. The attack complexity is rated as high, indicating that specific conditions or system configurations must align for successful exploitation. What distinguishes this flaw is its scope change: while the vulnerability exists in PeopleSoft, a successful compromise can significantly affect additional products in the environment. The impacts include high-severity confidentiality and integrity violations—attackers can both exfiltrate and modify critical data accessible through PeopleSoft Enterprise PT PeopleTools.

Business impact

This vulnerability poses a material risk to organizations relying on PeopleSoft for human capital management, financials, or supply chain operations. Unauthorized data modification could corrupt payroll records, financial transactions, or employee information, leading to operational disruption and potential regulatory violations. The confidentiality impact allows exfiltration of sensitive employee, financial, or vendor data, creating breach notification obligations and reputational harm. Because the scope extends beyond PeopleSoft itself, compromised systems could serve as a pivot point for attackers to access downstream systems, multiplying the blast radius. Organizations should prioritize assessment and patching to prevent this vector from being weaponized in targeted or broad-based attacks.

Affected systems

PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 are confirmed affected. Organizations running these versions with internet-facing or network-accessible WebLogic instances are at direct risk. The scope change notation indicates that downstream systems integrated with or dependent on PeopleSoft data may also be indirectly compromised. Verify your current PeopleSoft version and deployment topology (whether WebLogic endpoints are exposed to untrusted networks) to determine your exposure level.

Exploitability

While the CVSS rating indicates this is difficult to exploit, the combination of network accessibility, no authentication requirement, and no user interaction needed makes it a serious threat. The 'difficult to exploit' classification likely reflects that particular system configurations, application states, or timing conditions must be present, but determined attackers with network access can conduct reconnaissance and targeted exploitation. Given that PeopleSoft systems are often internet-accessible for remote workforce support, this vulnerability should not be underestimated. No public exploit code is currently known to be circulating, but the HIGH CVSS score and detailed nature of the flaw mean security researchers and threat actors alike will likely develop functional proofs-of-concept.

Remediation

Consult Oracle's official security advisory for patched versions of PeopleSoft Enterprise PT PeopleTools that address this flaw. Typically, Oracle releases patches quarterly or more frequently for critical issues; verify the advisory for versions 8.61 and 8.62 that are no longer affected. Pending patch deployment, implement network-based mitigations: restrict HTTP/HTTPS access to PeopleSoft WebLogic endpoints to known, trusted IP ranges or VPN access only. Consider disabling unnecessary WebLogic features or endpoints. Apply defense-in-depth measures including web application firewalls (WAF) rules tuned to detect abnormal data access patterns on PeopleSoft interfaces.

Patch guidance

Check Oracle's official PeopleSoft security advisories and the MyOracle Support portal for patch availability for versions 8.61 and 8.62. Patches are typically released as cumulative updates or security bundles. Before applying, validate patch compatibility with your PeopleSoft environment, including customizations, integrations, and dependent systems. Establish a testing window in a non-production environment that mirrors your production topology. Schedule patching during a maintenance window when PeopleSoft batch processes and integrations can be safely suspended. Verify post-patch functionality, particularly WebLogic connectivity and data-access workflows, before returning systems to production.

Detection guidance

Monitor WebLogic logs and PeopleSoft audit trails for unauthorized data access, modification attempts, or deletion events from unauthenticated or unexpected sources. Inspect network traffic to PeopleSoft endpoints for unusual HTTP requests or repeated access attempts that may indicate reconnaissance. Implement or enhance endpoint detection and response (EDR) on PeopleSoft servers to capture process behavior, memory access patterns, and file modifications. Web application firewall (WAF) logs should be reviewed for probing or exploitation attempts targeting WebLogic administrative interfaces or known vulnerable parameter sets. Correlate alerts across network, application, and database layers to identify multi-stage attacks leveraging this flaw.

Why prioritize this

This vulnerability merits immediate prioritization due to its HIGH CVSS score (8.7), network accessibility without authentication, and potential for scope creep into downstream systems. Organizations with internet-facing PeopleSoft deployments face the highest risk. The lack of KEV listing does not diminish urgency; rather, it indicates that targeted, organized exploitation may be limited currently, but the window for rapid weaponization is narrow. Delaying patch application increases the probability of opportunistic compromise.

Risk score, explained

The CVSS 3.1 score of 8.7 reflects the following factors: (1) Network Attack Vector—the flaw is exploitable over the network with no physical access required; (2) High Attack Complexity—the difficult-to-exploit nature lowers the score somewhat, suggesting specific conditions must align; (3) No Authentication Required—unauthenticated attackers can trigger the vulnerability; (4) No User Interaction—no victim action is needed to expose the flaw; (5) Scope Change—the impact extends beyond PeopleSoft to other products, elevating severity; (6) High Confidentiality Impact—complete unauthorized disclosure of accessible data; (7) High Integrity Impact—unauthorized modification or deletion of data; (8) No Availability Impact—the flaw does not directly prevent system uptime. The combination of these factors, especially scope change and dual high impacts (C and I), justifies the HIGH severity rating.

Frequently asked questions

Should we apply this patch immediately, or can we wait for our next quarterly maintenance window?

Given the HIGH CVSS score and network accessibility without authentication, Oracle's typical guidance for HIGH-severity vulnerabilities is to apply patches as soon as practical—ideally within 30 days of availability. If your PeopleSoft environment is internet-facing or accessible from untrusted networks, prioritize patching within two weeks. Waiting until a quarterly window may expose you to active exploitation. Consult Oracle's published guidance and your enterprise patch management policy, but treat this as urgent rather than routine.

What does 'scope change' mean, and why does it matter for our risk assessment?

Scope change means that while the vulnerability exists within PeopleSoft Enterprise PT PeopleTools, a successful attack can impact other products or systems outside of PeopleSoft itself. In practice, this could mean an attacker compromises PeopleSoft and then uses that foothold to access integrated systems (e.g., financial, HR, supply chain systems) or pivot laterally across your network. This multiplies the potential blast radius beyond a single product and should elevate your perceived risk and urgency of remediation.

Our PeopleSoft WebLogic instance is behind a corporate firewall and not directly internet-accessible. Are we still at risk?

Yes, but your risk is lower. Internal network access from compromised workstations, supply chain partners with VPN access, or insiders could still exploit this flaw. Additionally, if your firewall rules inadvertently expose the endpoint or if an internal system is already compromised, this vulnerability becomes a secondary attack vector. Implement the principle of least privilege: restrict WebLogic access even internally to users and systems that legitimately require it. Patching remains essential because internal threats and lateral movement are real vectors.

Is there a workaround if we cannot patch immediately?

No complete workaround eliminates the risk. However, mitigating controls can reduce exposure: (1) Restrict network access to WebLogic endpoints via firewall rules, allowing only trusted IPs; (2) Implement WAF rules to detect and block suspicious HTTP patterns; (3) Enhance monitoring and logging to detect exploitation attempts; (4) Disable unnecessary WebLogic features or administrative interfaces if business operations allow. These measures lower risk but do not eliminate the underlying vulnerability. Patch deployment should remain your primary goal.

This analysis is provided for informational purposes to assist security professionals in risk assessment and remediation planning. The details and patch guidance herein are based on publicly available information from CVE-2026-35271 and Oracle's security advisories; always verify patch availability, compatibility, and applicability to your specific environment by consulting the official Oracle PeopleSoft security advisory and your vendor support channels. This document does not constitute legal, compliance, or IT advice. Organizations must adapt guidance to their unique architectures, policies, and regulatory obligations. No exploit code or weaponized proof-of-concept is provided herein. Timelines and recommendations are general; consult your enterprise risk management and security teams for prioritization specific to your organization. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).