Description
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools and permits an unauthenticated attacker to execute code via HTTP requests. Successful exploitation results in complete takeover of the PeopleSoft application, allowing the attacker to read, modify, or delete any data and disrupt service availability. The flaw demonstrates a severe breach of confidentiality, integrity, and availability and is classified as an Implicit Access Control weakness.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise PT PeopleTools, specifically versions 8.61 and 8.62, are affected. These versions include the Performance Monitor component that is vulnerable to the described exploit.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests low current exploitation probability, yet the fact that the vulnerability is unauthenticated and reachable over HTTP makes it easily exploitable in environments where network segmentation is inadequate. The vulnerability is not listed in the CISA KEV catalog, but its impact warrants immediate attention. Attackers can leverage standard HTTP traffic to reach the exposed component, making the exploitation path straightforward when direct network access to the PeopleSoft instance is available.

Generated by OpenCVE AI on June 17, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch covering PeopleSoft PT PeopleTools 8.61 and 8.62; the vendor publishes an update that addresses the Performance Monitor flaw.
  • Restrict HTTP access to PeopleSoft PT PeopleTools by limiting inbound traffic to trusted IP ranges or implementing a VPN tunnel to isolate the application from the public network.
  • If the Performance Monitor component is not required for business operations, disable or uninstall it to eliminate the attack surface.

Generated by OpenCVE AI on June 17, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Pt Peopletools
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.61:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.62:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Pt Peopletools
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Pt Peopletools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:54:47.945Z

Reserved: 2026-04-01T20:03:40.835Z

Link: CVE-2026-35278

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T05:15:03Z

Weaknesses

No weakness.