Description
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-06-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle PeopleSoft Enterprise PT PeopleTools application, specifically affecting web services that process HTTP requests. An unauthenticated attacker can exploit this flaw to perform critical data operations—creating, deleting, or modifying records—and can also gain full view or control of all accessible data within PeopleSoft. Because the flaw allows actions without prior authentication, the confidentiality and integrity of enterprise data are severely compromised. The primary weakness underpinning the attack is improper access control, which permits privilege escalation through web interfaces.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PT PeopleTools version 8.61 and 8.62 are affected. These versions are deployed in various enterprise environments that rely on the PeopleSoft toolset for business operations. If a system uses either of these releases, it is susceptible to the described exploitation, even if the attack is carried out against other interconnected applications due to the scope change potential.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity with major confidentiality and integrity impacts. The EPSS score of less than 1% shows a low probability of exploitation in the wild, but the lack of a KEV listing does not preclude targeted attacks. The exploitation requires only network reachability to the PeopleSoft HTTP endpoint and no user authentication. Given these constraints, organizations that expose PeopleSoft to external networks or have weak perimeter controls pose a higher risk, whereas those that tightly control internal access may see a reduced threat level.

Generated by OpenCVE AI on June 17, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for PeopleSoft Enterprise PT PeopleTools 8.61 and 8.62 as soon as it becomes available
  • Restrict HTTP access to the PeopleSoft web services by limiting traffic to trusted IP ranges or VPN endpoints
  • Enforce strong authentication and authorization policies on the PeopleSoft application, ensuring that only authorized users may perform critical data operations
  • Deploy application layer firewalls or ACLs that block anomalous request patterns directed at the affected endpoints
  • Continuously monitor application logs for unusual data access or modification activities and investigate promptly

Generated by OpenCVE AI on June 17, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Pt Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Pt Peopletools
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Pt Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:13:59.225Z

Reserved: 2026-04-01T20:03:40.835Z

Link: CVE-2026-35271

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T01:30:04Z

Weaknesses

No weakness.