Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35278 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-35278 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35278 is a critical unauthenticated remote vulnerability affecting the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62.

Technical Detail

The flaw resides in the Performance Monitor component of PeopleTools and is described by Oracle as easily exploitable by an unauthenticated attacker with network access, requiring no user interaction or prior privileges. The exact technical mechanism has not been fully disclosed in public advisories, but the CVSS score of 9.8 and the unauthenticated network attack vector indicate a high likelihood of remote code execution or complete compromise of the affected component. Successful exploitation could result in full confidentiality, integrity, and availability impact on the targeted PeopleSoft instance.

Exploitation Status

No known exploit code has been observed or confirmed as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is assessed as none at this time, though the low attack complexity and unauthenticated attack surface make this a high-priority candidate for future exploitation development.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE in available intelligence sources.

What To Do

Apply Oracle's patch for PeopleTools 8.61 and 8.62 as released through the Oracle Critical Patch Update cycle. Given the critical CVSS score of 9.8 and the unauthenticated network-accessible attack surface, patching should be treated as high priority and completed without delay. Organizations that cannot patch immediately should restrict network access to the Performance Monitor component at the perimeter and application firewall level, limiting exposure to trusted internal networks only. Monitor application and network logs for anomalous unauthenticated requests targeting PeopleTools Performance Monitor endpoints. Verify patch application through Oracle's standard patch validation procedures and confirm version currency across all PeopleSoft instances in the environment.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →