Known vulnerability record

CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Stable IDcve:CVE-2026-35273Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

Keep the signals separate

CVSS severitycriticalScore 9.8 · source oracle
EPSS probability95.5%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-06-12
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-06-11
CVE modified
2026-08-04
KEV date added
2026-06-12
Dataset fetched
2026-08-21T03:54:57.309Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.