PT-2026-48612 · Oracle · Peoplesoft Enterprise Peopletools

CVE-2026-35273

·

Published

2026-06-10

·

Updated

2026-07-17

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.62
Description An unauthenticated remote code execution flaw exists in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. An attacker with network access via HTTP can send a specially crafted request to the Environment Management Hub to execute arbitrary code and potentially take over the system. This issue was exploited as a zero-day between May 27 and June 9, 2026, by threat actors including ShinyHunters and Cl0p. The campaign primarily targeted higher education institutions, with over 100 organizations affected. In one confirmed incident, the University of Nottingham suffered a breach where approximately 40 GB of data, including personal information and payment details of 455,000 students and alumni, were stolen.
Recommendations For versions 8.61 through 8.62, apply the emergency fix provided in the Oracle advisory. Restrict access to the affected endpoints and harden access controls to minimize the risk of exploitation. Implement vigilant monitoring and detection practices to identify unusual data exfiltration patterns and review access logs. As a temporary mitigation, restrict the use of the Environment Management Hub until the patch is fully deployed.

Exploit

Fix

DoS

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08250
CVE-2026-35273
ZDI-26-387
ZDI-26-388
ZDI-26-389

Affected Products

Peoplesoft Enterprise Peopletools