Skip to content
COOEY

FAIL › dossier

PeopleSoft Enterprise PeopleTools

PRODUCT

· dossier confidence 50%

PeopleSoft Enterprise PeopleTools is a business management platform by Oracle with a critically compromised security posture due to severe, unpatched vulnerabilities in core components. The lack of authentication for critical functions allows unauthenticated attackers to gain full system control, representing a significant risk to organizations relying on this software.

PROFILE
CategoryEnterprise SoftwareWhat they doPeopleSoft Enterprise PeopleTools is a business management software platform developed by Oracle.
SECURITY POSTURE

The security posture is critically compromised by severe, unpatched vulnerabilities in core components, specifically lacking authentication for critical functions which allows unauthenticated attackers to gain full system control.

Notable failures
  • CVE-2026-35273: Unauthenticated RCE in PeopleTools
  • CVE-2019-2725: Critical vulnerability in WebLogic Server component
Patterns: critical unpatched RCEs in core components; lack of authentication for critical functions
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-06-12 CVE-2026-35273 critical Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control.
2019-04-26 CVE-2019-2725 critical CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
Open questions: Are there other unpatched vulnerabilities in PeopleTools? · What is the current patch status for CVE-2026-35273?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 03:59:58.736219+00:00