HIGH 8.4

CVE-2026-35272: Oracle PeopleSoft PT PeopleTools Local Privilege Escalation

Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 contain a local privilege escalation vulnerability in the Deployment Package component. An attacker with legitimate access to the infrastructure hosting PeopleSoft can exploit this flaw without authentication to gain complete control over the PeopleSoft system, compromising confidentiality, integrity, and availability. The vulnerability carries a CVSS score of 8.4 (HIGH severity).

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.4 HIGH · CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-269
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-24

NVD description (verbatim)

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-35272 is a local privilege escalation vulnerability affecting PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. The issue resides in the Deployment Package component and is classified under CWE-269 (Improper Access Control). The attack vector is local (AV:L), requires no special conditions (AC:L), no privileges (PR:N), and no user interaction (UI:N). Successful exploitation results in complete system compromise with high impact across confidentiality (C:H), integrity (I:H), and availability (A:H). The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog.

Business impact

Compromise of PeopleSoft systems can expose sensitive human resources, payroll, and financial data, disrupt critical business processes, and potentially trigger compliance violations. Since PeopleSoft manages core enterprise functions including employee records and financial transactions, an attacker gaining full system control poses severe operational and reputational risk. Organizations relying on PeopleSoft for HR and financial operations should treat this as a high-priority threat due to the sensitive nature of data typically stored in these systems.

Affected systems

Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 are affected. Organizations running these specific versions should immediately check their deployment inventory. Later versions and earlier versions outside this range are not mentioned as vulnerable in the advisory. Verify your exact PeopleSoft version in your environment to determine if you are in scope.

Exploitability

This vulnerability is exploitable by any attacker with local access to the infrastructure—such as a compromised employee account, contractor access, or lateral movement from another compromised system. The attack requires no special privileges, no complex conditions, and no user interaction, making it relatively straightforward to exploit once access to the host is obtained. The local requirement significantly reduces the attack surface compared to remote exploits, but organizations should not underestimate the risk given the prevalence of insider threats and lateral movement in breach scenarios.

Remediation

Upgrade affected PeopleSoft Enterprise PT PeopleTools installations from versions 8.61 or 8.62 to a patched version released by Oracle. Verify the specific patch version number and availability date against Oracle's official security advisory. In parallel, apply defense-in-depth controls: restrict local access to PeopleSoft infrastructure, enforce strong authentication and access controls, monitor privileged account activity, and segment the PeopleSoft environment from less-trusted network zones.

Patch guidance

Consult Oracle's official PeopleSoft security advisory for the exact patched version numbers and release dates. Patch testing should focus on regression testing in lower environments first, given PeopleSoft's criticality to HR and finance operations. Coordinate patching with your change management process to minimize business disruption. Verify that your patch also addresses any related or dependent components in your PeopleSoft deployment.

Detection guidance

Monitor PeopleSoft systems for unusual privilege escalation attempts, unexpected process execution in sensitive directories, and anomalous activity from service accounts. Log and alert on failed and successful authentication attempts targeting the Deployment Package component. Use endpoint detection and response (EDR) tools to identify suspicious local execution patterns. Audit access logs for unauthorized modifications to system files or configurations. Consider implementing file integrity monitoring on critical PeopleSoft binaries and configuration files.

Why prioritize this

This vulnerability merits immediate prioritization because it enables complete system takeover with minimal attacker effort (no special privileges or complex exploitation required), affects widely-deployed enterprise software managing sensitive data, and has a high CVSS score of 8.4. Although it requires local access, the combination of zero-privilege requirement and full system compromise potential—coupled with the strategic importance of PeopleSoft in most enterprises—makes it a critical risk. The fact that it is not yet on CISA's KEV list does not diminish the threat; proactive patching is essential to prevent exploitation.

Risk score, explained

The CVSS 3.1 score of 8.4 (HIGH) reflects the severity of full system compromise with high impact to confidentiality, integrity, and availability. Although the attack vector is local (reducing the score compared to network-based exploits), the absence of privilege requirements, attack complexity, or user interaction significantly elevates the risk. The score appropriately captures a scenario where any user on the compromised host can escalate to full system control.

Frequently asked questions

Does this vulnerability require authentication to PeopleSoft itself?

No. The vulnerability is exploitable by an unauthenticated attacker who has local access to the infrastructure where PeopleSoft executes. This means someone with an operating system account on the PeopleSoft server (or who gains one through lateral movement) can exploit it without needing PeopleSoft application credentials.

Are versions earlier than 8.61 or later than 8.62 affected?

Only versions 8.61 and 8.62 are listed as vulnerable in this advisory. Always verify your exact installed version and cross-reference it against Oracle's official security advisory, as patch availability and version lineage can vary.

What should organizations prioritize if they cannot patch immediately?

Implement strict access controls to limit who can log on to PeopleSoft infrastructure servers, enforce network segmentation, monitor for suspicious local activity, and apply compensating controls such as privileged access management (PAM) and enhanced logging. However, patching should remain the primary goal; compensating controls are temporary measures.

Is there public exploit code or active exploitation?

This vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, which suggests no evidence of widespread exploitation at the time of publication. However, the absence of public proof-of-concept code does not guarantee the vulnerability will not be exploited; organizations should patch regardless of current threat landscape information.

This analysis is based on the published CVE description and CVSS vector as of the modification date. Patch availability, version numbers, and remediation timelines should be verified against Oracle's official security advisory. This explainer is for informational purposes and does not constitute professional security advice. Organizations should conduct their own risk assessment and consult with Oracle support or qualified security professionals before implementing any remediation strategy. The absence of a vulnerability from CISA's Known Exploited Vulnerabilities catalog does not guarantee immunity from exploitation. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).