EXPOSURES › CVE-2026-35273
CVE-2026-35273
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control.
This critical vulnerability allows unauthenticated attackers to take over PeopleSoft Enterprise PeopleTools, a widely used ERP component in defense systems. The absence of authentication controls for critical functions creates a severe risk of data exfiltration and system compromise for DIB organizations relying on Oracle PeopleSoft. Immediate patching and network segmentation are required to mitigate this active exploitation threat.
Shame score — A critical authentication bypass in a widely deployed ERP system that enables unauthenticated takeover, directly linked to ransomware exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |