CVE-2026-35289: Oracle PeopleSoft PT PeopleTools Authentication Bypass (CVSS 8.1)
Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 contain a vulnerability in its Deployment Package component that allows an unauthenticated attacker to remotely compromise the system over HTTPS. Despite being difficult to exploit, successful attacks could result in complete system takeover, affecting confidentiality, integrity, and availability. The vulnerability stems from missing or insufficient authentication mechanisms (CWE-306), permitting network-based attacks without user interaction.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.1 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-306
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-24
NVD description (verbatim)
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35289 is a network-accessible authentication bypass or missing authentication check in PeopleSoft Enterprise PT PeopleTools Deployment Package. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates network attack surface, high attack complexity, no privileges required, no user interaction needed, and impacts to all three CIA triad components. The flaw is rooted in CWE-306 (Missing Authentication for Critical Function), suggesting the component fails to properly validate caller identity before executing sensitive operations. Affected versions are limited to 8.61 and 8.62.
Business impact
A successful exploit could grant an attacker unauthenticated control over PeopleSoft deployment infrastructure, potentially enabling lateral movement into HR, financial, or payroll systems that depend on PeopleSoft. This threatens data exfiltration (employee records, financial data), system manipulation (fraudulent transactions, unauthorized access provisioning), and prolonged downtime. Organizations relying on PeopleSoft for mission-critical business processes face operational disruption and regulatory exposure.
Affected systems
Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 are affected. Verify your deployment version in the PeopleSoft administration console or via vendor advisory. Versions outside this range and other Oracle PeopleSoft products should be evaluated for exposure through official Oracle security bulletins.
Exploitability
While marked as difficult to exploit (AC:H), the vulnerability requires only network access and HTTPS connectivity—no authentication or user interaction. The high attack complexity suggests the attacker must satisfy non-trivial preconditions (specific timing, crafted payloads, or environmental configuration), but the lack of authentication requirement means reconnaissance and exploitation attempts can be conducted without prior system access. Active in-the-wild exploitation is not yet documented in public KEV catalogs.
Remediation
Consult Oracle's official security advisory for patched versions of PeopleSoft Enterprise PT PeopleTools. Organizations should prioritize upgrading to the latest patched release, which may involve coordinating with PeopleSoft system administrators and scheduling maintenance windows. As an interim control, restrict HTTPS network access to the Deployment Package component to trusted administrative networks where feasible.
Patch guidance
Obtain and apply security patches from Oracle's PeopleSoft security updates page. Verify patch compatibility with your current PeopleSoft configuration and dependent systems before deployment. Test patches in a non-production environment, especially given the criticality of PeopleSoft to HR and financial operations. Coordinate with Oracle support to determine the specific patched version numbers for your affected release (8.61 or 8.62).
Detection guidance
Monitor HTTPS traffic to the PeopleSoft Deployment Package component for unauthenticated requests or unusual payload structures. Implement network-based intrusion detection rules targeting the CWE-306 pattern (calls to sensitive functions lacking authentication checks). Review web application firewall logs and PeopleSoft security audit trails for failed authentication attempts and unexpected deployments. Baseline normal administrative access patterns and flag deviations.
Why prioritize this
Despite difficult exploitability, the CVSS 8.1 score and full CIA impact warrant immediate attention. The unauthenticated network attack vector combined with high-consequence system takeover potential makes this a priority for organizations operating PeopleSoft 8.61 or 8.62 in production. Rapid inventory and patching reduces exposure window before threat actors develop reliable exploits.
Risk score, explained
CVSS 3.1 score of 8.1 (HIGH severity) reflects the critical consequence of system compromise balanced against elevated attack complexity. The vector shows an attacker needs only network access to trigger the vulnerability, but the AC:H component indicates obstacles in reliable exploitation—likely requiring specific environmental conditions or multi-step attack chains. This places the vulnerability in the upper-mid risk tier: too dangerous to defer, but not immediately critical if network controls are in place.
Frequently asked questions
What versions of PeopleSoft are affected by this vulnerability?
Only versions 8.61 and 8.62 of Oracle PeopleSoft Enterprise PT PeopleTools are listed as affected. If your organization runs other versions or other PeopleSoft product lines, consult Oracle's official security advisory to confirm your exposure status.
Can an attacker exploit this remotely without any credentials?
Yes. The vulnerability requires no authentication or user interaction—an attacker with network access via HTTPS can attempt exploitation. However, the attack complexity is marked as high, indicating the attacker must overcome technical obstacles to reliably compromise the system.
Is there public exploit code available for this vulnerability?
As of the latest advisory update on June 24, 2026, this vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog and public exploit code is not widely documented. Nevertheless, organizations should not rely on obscurity; patching should proceed urgently.
What should we do if we cannot patch immediately?
Implement network segmentation to restrict HTTPS access to the Deployment Package to authorized administrative sources only. Enable web application firewall rules to block suspicious requests. Increase monitoring of authentication and deployment activities. Develop a patch timeline with your PeopleSoft team and Oracle support.
This analysis is based on Oracle's official CVE description and CVSS scoring as of June 24, 2026. Specific patch version numbers, detailed attack prerequisites, and confirmed exploitation activity should be verified against Oracle's latest security advisories and threat intelligence feeds. This explainer does not constitute legal, compliance, or vendor-specific advice. Organizations should validate all remediation steps in test environments before production deployment and consult with their PeopleSoft vendor support team. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35265HIGHOracle Identity Manager Authentication Bypass – Critical Patch Required
- CVE-2026-35267HIGHOracle Identity Manager REST WebServices Authentication Bypass (CVSS 8.8)
- CVE-2026-35274HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass
- CVE-2026-35276HIGHOracle PeopleSoft Authentication Bypass Vulnerability (8.1 CVSS)
- CVE-2026-35279HIGHPeopleSoft PT PeopleTools Authentication Bypass – Critical Patch Guidance
- CVE-2026-35295HIGHOracle WebCenter Sites Authentication Bypass – High Risk Patch Alert
- CVE-2026-35299HIGHOracle WebLogic Server Console Authentication Bypass (CVSS 8.8)
- CVE-2026-35303HIGHWebLogic Server Console Vulnerability – Patch & Detection Guide