Summary
CVE-2026-35289 is a high-severity vulnerability in the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools, affecting versions 8.61 and 8.62. Published on June 16, 2026 as part of Oracle’s June 2026 Critical Patch Update (CPU), the flaw can be exploited by an unauthenticated remote attacker over HTTPS to potentially achieve full system compromise. The vulnerability carries a CVSS v3.1 base score of 8.1 (HIGH), with all three impact dimensions — confidentiality, integrity, and availability — rated HIGH.
Technical details
- Root cause: A security weakness in the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools, reachable over HTTPS without any prior authentication or user interaction.
- Trigger conditions: Attack Complexity is rated HIGH (AC:H), meaning exploitation requires specific non-default conditions to be present in the target environment. Oracle describes the vulnerability as "difficult to exploit"; however, enterprise PeopleSoft deployments vary widely in configuration, and affected instances exist across customer environments.
- Attack vector: Network (HTTPS) — remotely exploitable without credentials and without requiring any user interaction on the target system.
- Impact: Successful exploitation results in HIGH impact across confidentiality, integrity, and availability. According to Oracle’s advisory, exploitation can lead to complete compromise of the affected PeopleSoft instance, including potential full system takeover.
Affected software
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61
- Oracle PeopleSoft Enterprise PT PeopleTools 8.62
Severity
CVSS v3.1 Base Score: 8.1 (HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle June 2026 Critical Patch Update (CPU), which contains the patch for CVE-2026-35289. Oracle strongly advises customers to apply all CPU patches "without delay."
- If patching is not immediately possible: Restrict external HTTPS access to PeopleSoft Deployment Package endpoints at the network perimeter to reduce exposure. This vulnerability is published in the same CPU cycle as CVE-2026-35273 (CVSS 9.8), a related PeopleSoft flaw in the Updates Environment Management Hub component that has been actively exploited in the wild — reinforcing the urgency of hardening internet-facing PeopleSoft infrastructure without delay.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

