Summary
CVE-2026-35278 is a critical, unauthenticated remote code execution vulnerability residing in the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools, affecting versions 8.61 and 8.62. With a CVSS 3.1 base score of 9.8 (Critical), the flaw requires no authentication and no user interaction, enabling any network-accessible attacker to fully compromise the affected system over HTTP. Oracle addressed this vulnerability in its June 2026 Critical Security Patch Update (CSPU), released the same day as a separate out-of-band alert for CVE-2026-35273 — another critical flaw in the same product that has been actively exploited in the wild by the threat actor UNC6240 (ShinyHunters), breaching more than 100 organizations.
Technical details
- Root cause: An easily exploitable flaw in the Performance Monitor component of PeopleSoft Enterprise PT PeopleTools allows unauthenticated remote attackers to compromise the system via HTTP. No CWE classification has been assigned at this time.
- Trigger conditions: The vulnerability is reachable over the network without any prior authentication or user interaction, and requires only low attack complexity to exploit.
- Attack vector: Network-accessible via HTTP; no credentials, special privileges, or local access are required.
- Impact: Full compromise across confidentiality, integrity, and availability (C:H/I:H/A:H), consistent with complete system takeover.
Affected software
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61
- Oracle PeopleSoft Enterprise PT PeopleTools 8.62
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s June 2026 Critical Security Patch Update (CSPU). Patch installation instructions are available through My Oracle Support document CPU167.
- If immediate patching is not feasible, restrict network-level access to PeopleSoft infrastructure — including HTTP endpoints — from untrusted networks and internet-facing paths as an interim measure.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

