FAIL › dossier
PeopleSoft Enterprise PeopleTools
PRODUCT· dossier confidence 50%
PeopleSoft Enterprise PeopleTools is a business management platform by Oracle with a critically compromised security posture due to severe, unpatched vulnerabilities in core components. The lack of authentication for critical functions allows unauthenticated attackers to gain full system control, representing a significant risk to organizations relying on this software.
PROFILE
CategoryEnterprise SoftwareWhat they doPeopleSoft Enterprise PeopleTools is a business management software platform developed by Oracle.
SECURITY POSTURE
The security posture is critically compromised by severe, unpatched vulnerabilities in core components, specifically lacking authentication for critical functions which allows unauthenticated attackers to gain full system control.
Notable failures
- CVE-2026-35273: Unauthenticated RCE in PeopleTools
- CVE-2019-2725: Critical vulnerability in WebLogic Server component
Patterns: critical unpatched RCEs in core components; lack of authentication for critical functions
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-12 | CVE-2026-35273 | critical | Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control. |
| 2019-04-26 | CVE-2019-2725 | critical | CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar |
Open questions: Are there other unpatched vulnerabilities in PeopleTools? · What is the current patch status for CVE-2026-35273?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 03:59:58.736219+00:00