Summary
CVE-2026-35273 is a critical missing authentication vulnerability (CWE-306) in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. With a CVSS v3.1 base score of 9.8, an unauthenticated remote attacker can send a crafted HTTP request to the vulnerable component with no user interaction required, resulting in complete system takeover. Oracle issued an out-of-band Security Alert on June 11, 2026; Mandiant’s CTO has publicly warned of active zero-day exploitation in the wild.
Technical details
- Root cause: Missing authentication for a critical function (CWE-306) in the Updates Environment Management component, allowing security-sensitive operations to be reached without any credential validation
- Trigger conditions: An unauthenticated HTTP request to the vulnerable Updates Environment Management endpoint — no credentials, no user interaction, and no special network positioning required; Oracle explicitly describes this as "easily exploitable"
- Attack vector: Network-accessible via HTTP with low attack complexity and no privileges required (AV:N/AC:L/PR:N/UI:N), making exploitation achievable by any remote attacker against internet-facing deployments
- Impact: Full system takeover — successful exploitation results in complete compromise of confidentiality, integrity, and availability of the affected PeopleSoft Enterprise PeopleTools installation, equivalent to remote code execution
Affected software
- Oracle PeopleSoft Enterprise PeopleTools 8.61
- Oracle PeopleSoft Enterprise PeopleTools 8.62
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s official mitigations as documented in the Oracle Security Alert Advisory for CVE-2026-35273. Oracle states that "implementation of the recommended mitigations [is] a high-priority risk reduction measure" and strongly recommends immediate action; full remediation details are accessible via Oracle’s customer support portal.
- If immediate remediation is not feasible: Restrict network-level access to PeopleSoft PeopleTools servers by blocking untrusted and internet-facing HTTP/HTTPS access to the Updates Environment Management component. Ensure PeopleSoft instances are not directly reachable from the public internet while remediation is underway.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

