Missing authentication in Oracle PeopleSoft (PeopleTools) (CVE-2026-35273) — unauthenticated takeover, used in ransomware
Oracle PeopleSoft Enterprise PeopleTools — the platform under the PeopleSoft ERP (HR, finance) — has a missing-authentication-for-critical-function flaw (CWE-306). A remote, unauthenticated attacker can take over PeopleTools. CISA listed it as known-exploited (KEV) and confirmed ransomware use (CVSS 9.8 Critical, per NVD).
Key facts
- CVE IDCVE-2026-35273
- CVSS base score9.8 CRITICAL
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)Oracle PeopleSoft Enterprise PeopleTools
- CWECWE-306
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-06-15 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Missing authentication for a critical function (CWE-306) in PeopleTools, the platform under PeopleSoft
- A remote, unauthenticated attacker can take over PeopleTools
- Listed in CISA KEV = exploitation confirmed; also confirmed used in ransomware
- NVD base score 9.8 Critical (no auth, low complexity, severe C/I/A)
- Response: apply Oracle's fix; federal remediation deadline was June 15, 2026 (top priority)
- Of the 1,687 records held as of 2026-09-01, 37 carry CWE-306 (missing authentication for a critical function) first.
1The PeopleSoft Enterprise flaw
CVE-2026-35273 is a Missing Authentication for Critical Function vulnerability (CWE-306) in Oracle PeopleSoft Enterprise PeopleTools. PeopleSoft is an enterprise resource planning (ERP) system for HR, payroll, finance, procurement, and campus operations; PeopleTools is the development/runtime platform beneath it.
2The impact CISA describes
Per CISA, the flaw lets an unauthenticated attacker achieve takeover of PeopleSoft Enterprise PeopleTools. "Missing authentication" means a critical function that should require authentication can be reached and executed without it. Because core systems concentrate sensitive HR, payroll, and finance data, a takeover has broad impact.
3Exploitation in ransomware campaigns
The flaw is network-reachable with low complexity and no authentication, with severe impact to confidentiality, integrity, and availability. CISA has further confirmed that this vulnerability is used in ransomware campaigns.
4Missing authentication as a class
Missing authentication for a critical function (CWE-306) is the flaw where a function that ought to require authentication can be reached and run without it. It accounts for a definite share of the KEV records.
PeopleSoft is the enterprise core system handling human resources, payroll, finance, procurement and university administration, with PeopleTools as its development and runtime foundation. Core systems concentrate sensitive information, so being taken over reaches broadly. Network access, low complexity and no authentication combine with severe impact to confidentiality, integrity and availability alike.
Why it matters
A core system holding sensitive HR and finance data can be taken over without authentication, and ransomware use is confirmed. Enterprises, universities, and agencies running PeopleSoft should inventory external exposure, patch immediately, and review logs. It reflects the reality of attacks on core business systems.
FAQ
What are PeopleSoft and PeopleTools?
What is a "missing authentication" flaw?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).