Critical Known exploited (KEV) Ransomware use CVE-2026-35273

Missing authentication in Oracle PeopleSoft (PeopleTools) (CVE-2026-35273) — unauthenticated takeover, used in ransomware

Oracle PeopleSoft Enterprise PeopleTools Added to KEV Jun 12, 2026 Federal remediation due 2026-06-15

Oracle PeopleSoft Enterprise PeopleTools — the platform under the PeopleSoft ERP (HR, finance) — has a missing-authentication-for-critical-function flaw (CWE-306). A remote, unauthenticated attacker can take over PeopleTools. CISA listed it as known-exploited (KEV) and confirmed ransomware use (CVSS 9.8 Critical, per NVD).

Key facts

  • CVE IDCVE-2026-35273
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Oracle PeopleSoft Enterprise PeopleTools
  • CWECWE-306
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-06-15 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Missing authentication for a critical function (CWE-306) in PeopleTools, the platform under PeopleSoft
  • A remote, unauthenticated attacker can take over PeopleTools
  • Listed in CISA KEV = exploitation confirmed; also confirmed used in ransomware
  • NVD base score 9.8 Critical (no auth, low complexity, severe C/I/A)
  • Response: apply Oracle's fix; federal remediation deadline was June 15, 2026 (top priority)
  • Of the 1,687 records held as of 2026-09-01, 37 carry CWE-306 (missing authentication for a critical function) first.

1The PeopleSoft Enterprise flaw

CVE-2026-35273 is a Missing Authentication for Critical Function vulnerability (CWE-306) in Oracle PeopleSoft Enterprise PeopleTools. PeopleSoft is an enterprise resource planning (ERP) system for HR, payroll, finance, procurement, and campus operations; PeopleTools is the development/runtime platform beneath it.

2The impact CISA describes

Per CISA, the flaw lets an unauthenticated attacker achieve takeover of PeopleSoft Enterprise PeopleTools. "Missing authentication" means a critical function that should require authentication can be reached and executed without it. Because core systems concentrate sensitive HR, payroll, and finance data, a takeover has broad impact.

3Exploitation in ransomware campaigns

The flaw is network-reachable with low complexity and no authentication, with severe impact to confidentiality, integrity, and availability. CISA has further confirmed that this vulnerability is used in ransomware campaigns.

4Missing authentication as a class

Missing authentication for a critical function (CWE-306) is the flaw where a function that ought to require authentication can be reached and run without it. It accounts for a definite share of the KEV records.

Records whose first CWE is CWE-30637of the 1,687 held as of 2026-09-01
Known to be used in ransomware352this record among them
Remediation date15 June 2026

PeopleSoft is the enterprise core system handling human resources, payroll, finance, procurement and university administration, with PeopleTools as its development and runtime foundation. Core systems concentrate sensitive information, so being taken over reaches broadly. Network access, low complexity and no authentication combine with severe impact to confidentiality, integrity and availability alike.

Why it matters

A core system holding sensitive HR and finance data can be taken over without authentication, and ransomware use is confirmed. Enterprises, universities, and agencies running PeopleSoft should inventory external exposure, patch immediately, and review logs. It reflects the reality of attacks on core business systems.

FAQ

What are PeopleSoft and PeopleTools?
PeopleSoft is an enterprise ERP for HR, payroll, finance, and university operations. PeopleTools is the development/runtime platform beneath it that supports the whole PeopleSoft application.
What is a "missing authentication" flaw?
A critical function that should require authentication can be reached and executed without it — so an attacker may operate or take over the system without logging in.
What should I do?
Check Oracle's official advisory for affected versions and apply the fix. Given confirmed ransomware use, prioritize it and review external exposure and access logs.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Oracle#PeopleSoft#ERP#Missing authentication#Ransomware
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.