PT-2026-48612 · Oracle · Peoplesoft Enterprise Peopletools
CVE-2026-35273
·
Published
2026-06-10
·
Updated
2026-07-17
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.62
Description
An unauthenticated remote code execution flaw exists in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. An attacker with network access via HTTP can send a specially crafted request to the Environment Management Hub to execute arbitrary code and potentially take over the system. This issue was exploited as a zero-day between May 27 and June 9, 2026, by threat actors including ShinyHunters and Cl0p. The campaign primarily targeted higher education institutions, with over 100 organizations affected. In one confirmed incident, the University of Nottingham suffered a breach where approximately 40 GB of data, including personal information and payment details of 455,000 students and alumni, were stolen.
Recommendations
For versions 8.61 through 8.62, apply the emergency fix provided in the Oracle advisory.
Restrict access to the affected endpoints and harden access controls to minimize the risk of exploitation.
Implement vigilant monitoring and detection practices to identify unusual data exfiltration patterns and review access logs.
As a temporary mitigation, restrict the use of the Environment Management Hub until the patch is fully deployed.
Exploit
Fix
DoS
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peoplesoft Enterprise Peopletools