CVE-2026-35288Disclosure(oracle / peoplesoft_enterprise_pt_peopletools)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • peoplesoft_enterprise_pt_peopletools

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
peoplesoft_enterprise_pt_peopletools

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-17: 1Technical Details · 2026-06-17: 106-17
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-35288 Privilege Escalation in #Oracle @Oracle PeopleSoft High privileged attacker can compromise system and impact additional products #CVSS 8.2 Mitigate immediately #infosec #cybersecurity #hackers #devsecops #devops #developers #linux info: https://www.valtersit.com/cve/CVE-2026-35288/

    Post summary

    The tweet announces a privilege‑escalation flaw (CVE‑2026‑35288) in Oracle PeopleSoft with a CVSS score of 8.2 and urges immediate mitigation, but it offers no PoC, exploit code, or patch details.

    0000068
    935 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclepeoplesoft_enterprise_pt_peopletools8.61--
Apporaclepeoplesoft_enterprise_pt_peopletools8.62--

Explore more