Article

    Cyber News / Article / A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution

    A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution
    -2026-06-11

    A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution

    A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow an attacker with network access via HTTP to completely takeover the software. PeopleSoft is an integrated enterprise resource planning (ERP) software suite widely used by large organizations for managing core business functions, including HR, payroll, finance, supply chain, and campus operations. Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.

    Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.

    A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow for remote code execution. Details of the vulnerability are as follows:

    Tactic: Initial Access (TA0001):

    Technique: Exploit Public-Facing Application (T1190):

    Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise. It does not require authentication or user interaction, making it particularly dangerous for internet-facing systems. (CVE-2026-35273)

    Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.

    We recommend the following actions be taken:

    Copyright©2026 Center for Internet Security®

    Original source