Cyber News / Article / A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution

A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution
A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow an attacker with network access via HTTP to completely takeover the software. PeopleSoft is an integrated enterprise resource planning (ERP) software suite widely used by large organizations for managing core business functions, including HR, payroll, finance, supply chain, and campus operations. Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.
Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow for remote code execution. Details of the vulnerability are as follows:
Tactic: Initial Access (TA0001):
Technique: Exploit Public-Facing Application (T1190):
Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise. It does not require authentication or user interaction, making it particularly dangerous for internet-facing systems. (CVE-2026-35273)
Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.
We recommend the following actions be taken:
Copyright©2026 Center for Internet Security®
Related articles
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
2 days ago
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
2 days ago
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
2 days ago
