CVE-2026-35273 Scanner
CVE-2026-35273 Scanner - Remote Code Execution (RCE) vulnerability in Oracle PeopleSoft PeopleTools
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
3 weeks
Scan only one
Domain, Subdomain, IPv4
Toolbox
Oracle PeopleSoft PeopleTools is a versatile toolkit used by enterprises for managing all aspects of PeopleSoft applications. It is widely employed by HR and financial service departments for managing employee information and conducting core financial operations. PeopleSoft is mainly used by medium to large enterprises operating in various sectors like finance, education, and healthcare. The PeopleTools application ensures seamless integration with PeopleSoft applications, enhancing the overall user experience and efficiency. It provides functionality for workflow automation and is integral to organizations for handling human resources, customer relations, and supply chain management. Consequently, ensuring its security is paramount to preventing unauthorized system manipulations.
The detected vulnerability is a form of Remote Code Execution (RCE) found within Oracle PeopleSoft PeopleTools, specifically in the Updates Environment Management module. It allows unauthenticated attackers to execute arbitrary commands, thereby compromising system integrity. This form of vulnerability is critical because it permits attackers to potentially take over the system entirely. The flaw arises from improper handling of serialized data, leading to unchecked execution of malicious code. As the vulnerability is remotely exploitable, it poses a substantial risk of unauthorized system access, highlighting the need for immediate remediation.
Vulnerability Details indicate that the issue exists in the PSEMHUB component of PeopleTools. Specifically, it involves the deserialization of untrusted data through the hub endpoint found at /PSEMHUB/hub. The operation is performed using Java deserialization techniques, allowing attackers to send crafted payloads leading to arbitrary code execution. Successful exploitation of this vulnerability requires network access via HTTP, which the attackers can manipulate to gain control. The vulnerability also utilizes the DNS protocol to execute operations remotely, making it difficult to detect without specialized tools.
Exploiting this vulnerability can have significant and far-reaching impacts. An attacker who successfully exploits this vulnerability could gain full access to the underlying system, thereby compromising sensitive data and disrupting essential operations. Unauthorized access might lead to data theft, subsequent financial loss, and reputational damage to affected organizations. It can also result in unauthorized manipulation of application data, potentially resulting in cascading failures within the organization. Additionally, attackers can deploy further malware, causing further damage or using the compromised system as a pivot point for launching attacks against other targets.
REFERENCES
- https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
- https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
- https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/
- https://nvd.nist.gov/vuln/detail/CVE-2026-35273