HIGH 8.2

CVE-2026-35274: Oracle PeopleSoft PT PeopleTools Authentication Bypass

A vulnerability in Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 allows attackers to gain unauthorized access to sensitive data over the network without needing valid credentials. The flaw affects the Deployment Package component and can be exploited by simply sending HTTP requests from the internet. Attackers can read confidential information and modify certain data within the system, though they cannot disrupt availability. This is a network-accessible authentication bypass with meaningful data exposure and integrity risks.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Weaknesses (CWE)
CWE-306
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-24

NVD description (verbatim)

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-35274 is a missing authentication vulnerability in PeopleSoft Enterprise PT PeopleTools (CWE-306) affecting versions 8.61 and 8.62. The Deployment Package component fails to enforce proper authentication controls on HTTP endpoints, enabling unauthenticated remote network access. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) reflects network-based exploitation with no complexity requirements, no privileges needed, and no user interaction. High confidentiality impact indicates broad data exposure; limited integrity impact suggests write/modify access is restricted to a subset of accessible data. Availability is not affected.

Business impact

For organizations running PeopleSoft, this vulnerability poses immediate data breach risk. Exposed data could include employee records, compensation information, benefits data, and other HR/finance records typically housed in PeopleSoft systems. The integrity component means attackers could corrupt or falsify records, creating compliance violations and requiring forensic remediation. No mitigation through access controls—the flaw bypasses authentication entirely—means all exposed data on affected systems is at risk unless versions are patched or network segmentation isolates the vulnerable component. Regulatory exposure (GDPR, HIPAA, SOX) depends on data classification within each deployment.

Affected systems

PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 are vulnerable. Organizations should identify all instances of these versions in their environment, including development, test, and production systems. The vulnerability resides in the Deployment Package component, so any system using standard deployment mechanisms is affected. Air-gapped or internally-only PeopleSoft instances reduce immediate risk but remain vulnerable if network boundaries are later bridged or if internal attackers gain access.

Exploitability

This vulnerability is easily exploitable. Attackers require only network access (HTTP), no authentication credentials, no special privileges, and no user interaction. The attack surface is broad: any instance exposed to untrusted networks—including systems behind firewalls if lateral movement occurs—is at risk. No complexity in the exploit; standard HTTP requests suffice. The absence of a known public exploit or active exploitation (KEV status is false as of publication) does not diminish risk, as the simplicity of the attack vector makes weaponization trivial once disclosed.

Remediation

Apply security patches from Oracle PeopleSoft to versions 8.61 and 8.62 immediately. Verify patch availability and version guidance in the Oracle Security Advisory for CVE-2026-35274. Until patched, implement network segmentation to restrict HTTP access to the Deployment Package component to trusted administrative networks only. Disable remote deployment features if not actively in use. Implement Web Application Firewall (WAF) rules to block unauthenticated requests to known vulnerable endpoints. Monitor access logs for suspicious unauthenticated HTTP requests to PeopleSoft systems.

Patch guidance

Contact Oracle PeopleSoft support or consult the official security advisory for patch release dates and version numbers for 8.61 and 8.62. Patches should be tested in non-production environments before production deployment. Coordinate patching with change management windows, as PeopleSoft updates often require application downtime. Validate patch application by confirming authentication requirements are enforced on previously vulnerable endpoints. Document patch status across all environments (dev, test, production) to ensure complete coverage.

Detection guidance

Monitor HTTP access logs for unauthenticated requests to PeopleSoft Deployment Package endpoints. Watch for patterns of repeated failed authentication attempts or successful access from unexpected source IPs. Implement alerting on HTTP 200 responses to sensitive deployment-related URLs when no valid session exists. Use SIEM tools to correlate unusual data access patterns (large data exports, bulk modifications) coinciding with network traffic anomalies. Conduct periodic log reviews for evidence of exploitation prior to patch deployment. Scan network for exposed PeopleSoft instances using port and service fingerprinting.

Why prioritize this

This vulnerability merits immediate patching (within 48–72 hours) due to ease of exploitation, network accessibility, and high confidentiality impact. The absence of required authentication or user interaction eliminates traditional friction points for attackers. Data exposure scope is broad, affecting employee and financial records. The HIGH CVSS score (8.2) reflects significant risk. Organizations handling regulated data (healthcare, finance) face elevated compliance consequences. Although not yet in active exploit databases, simplicity of the attack method means rapid weaponization is probable.

Risk score, explained

CVSS 3.1 score of 8.2 (HIGH severity) reflects a network-accessible authentication bypass with substantial data confidentiality impact and limited integrity impact. The attack vector is network-based with low complexity, no privileges required, and no user interaction—all contributing to high exploitability. High confidentiality indicates attackers can access most or all PeopleSoft data; limited integrity (L) means modifications are constrained but still possible. Availability is unaffected. The score appropriately captures the severity of unauthorized data access but may understate business impact given typical PeopleSoft deployments house sensitive HR and financial information.

Frequently asked questions

Do we need to patch if PeopleSoft is only accessible from internal networks?

Yes. While internal-only deployments reduce exposure to external attackers, the vulnerability still exists and can be exploited by internal threat actors or following lateral movement from compromised systems. Patching is mandatory regardless of network position.

Can Web Application Firewall rules fully mitigate this vulnerability?

WAF rules can reduce attack surface by blocking unauthenticated requests to vulnerable endpoints, but they are not a reliable long-term substitute for patching. WAF configurations require careful tuning, monitoring, and updates. Authentication enforcement at the application layer (via patches) is the proper remediation.

What data is most at risk in a PeopleSoft compromise?

Employee records, compensation data, benefits information, payroll records, and business process data are typically at highest risk. The actual exposure depends on what data is loaded into each organization's PeopleSoft instance. Regulatory data (PII, health information in benefits systems) multiplies compliance impact.

Is this vulnerability actively being exploited?

As of the publication date, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, meaning no widespread active exploitation has been observed. However, ease of exploitation and network accessibility make weaponization probable if the vulnerability remains unpatched in discoverable systems.

This analysis is provided for informational purposes only and does not constitute legal, compliance, or professional security advice. Organizations should independently verify all patch version numbers, availability dates, and remediation guidance against official Oracle PeopleSoft security advisories. Risk scores and business impact assessments are based on the CVE description and CVSS rating and may not reflect your specific environment, data classification, or regulatory obligations. Consult your security team and compliance officers before implementing any remediation or detection measures. SEC.co makes no warranty regarding the completeness, accuracy, or timeliness of this intelligence. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).