Skip to content
Index
About
Articles
Radar
Contact
CVE
CISA KEV
CVE-2026-35273
Covered in 4 advisories
Radar advisories
2026-06-24
ZDI
ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability
The vulnerability in Oracle PeopleSoft's HttpListeningConnector permits unauthenticated remote attackers to trigger arbitrary server-side requests.
2026-06-24
ZDI
ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability
The vulnerability involves deserialization of untrusted data in Oracle PeopleSoft's HubMBeanPersistance component, with authentication bypass…
2026-06-24
ZDI
ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution Vulnerability
The advisory notes authentication is required but can be bypassed, which may expand the pool of potential attackers despite the need for initial…
2026-06-12
CISA
CISA KEV — Oracle PeopleSoft Enterprise PeopleTools (CVE-2026-35273)
The added vulnerability affects Oracle PeopleSoft Enterprise PeopleTools and involves missing authentication for a critical function.
References
NVD ↗
CVE.org ↗
CISA KEV catalogue ↗
listed as known exploited
Zero Day Initiative ↗