Summary
CVE-2026-35271 is a high-severity vulnerability affecting the WebLogic component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. An unauthenticated remote attacker with network access via HTTP can exploit this flaw to gain unauthorized read access to all accessible PeopleSoft data, as well as the ability to create, delete, or modify critical data within the platform. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) and is included among Oracle’s June 2026 Critical Patch Update security fixes.
Technical details
- Root cause: A flaw in the WebLogic component of PeopleSoft Enterprise PT PeopleTools allows exploitation without any prior authentication or user interaction.
- Trigger conditions: An attacker with network access via HTTP can trigger the vulnerability remotely; exploitation is rated as difficult (Attack Complexity: High), indicating specific conditions or knowledge are required.
- Attack vector: Network-accessible over HTTP; no credentials or user interaction are required.
- Scope change: Successful exploitation has scope-change implications, potentially affecting components beyond the immediately vulnerable PeopleSoft application.
- Impact: Successful exploitation can result in unauthorized creation, deletion, or modification of critical PeopleSoft data, as well as unrestricted read access to all accessible PeopleSoft Enterprise PT PeopleTools data. No availability impact has been assessed.
Affected software
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61
- Oracle PeopleSoft Enterprise PT PeopleTools 8.62
Severity
- CVSS v3.1 Base Score: 8.7 (High)
- Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate action: Apply the security patch released by Oracle as part of the June 2026 Critical Patch Update (CPU). Patch installation instructions are available through Oracle’s support portal (CPU167).
- Oracle strongly recommends applying this security patch without delay. Oracle has noted that successful attacks against its products have primarily targeted customers who had not applied available patches.
- Organizations unable to patch immediately should consider restricting inbound HTTP access to PeopleSoft WebLogic-facing endpoints at the network perimeter and reviewing access logs for anomalous unauthenticated activity.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

