# Oracle Issues Critical Warning on PeopleSoft Zero-Day Vulnerability Actively Exploited in Data Theft Campaign
Oracle has disclosed a critical zero-day vulnerability in its PeopleSoft Suite that allows unauthenticated remote code execution, with active exploitation confirmed in data theft attacks by the ShinyHunter threat group. The flaw, tracked as CVE-2026-35273, represents a severe risk to enterprise organizations worldwide that depend on PeopleSoft for human resources, payroll, and financial management.
## The Threat
The vulnerability enables attackers to execute arbitrary code on vulnerable PeopleSoft instances without requiring valid credentials, giving adversaries complete control over affected systems. According to Oracle's security advisory, the flaw has been actively exploited in the wild as part of targeted data theft operations attributed to ShinyHunter, a financially motivated threat group known for stealing corporate and personal data from large organizations.
Key characteristics of the threat:
Organizations operating PeopleSoft have been warned to treat this as an immediate security priority. The vulnerability appears in multiple versions of PeopleSoft Suite, affecting both on-premises and cloud deployments.
## Background and Context
PeopleSoft is one of the most widely deployed enterprise resource planning (ERP) and human capital management (HCM) systems globally, used by thousands of organizations across healthcare, finance, manufacturing, government, and retail sectors. The platform manages critical business functions including payroll processing, benefits administration, talent management, and financial reporting.
Historical context:
ShinyHunter's track record:
The threat group responsible for exploiting this vulnerability has claimed responsibility for data breaches affecting major retailers, financial institutions, and technology companies. The group typically:
The discovery of this zero-day in active use suggests ShinyHunter has maintained undisclosed access to PeopleSoft vulnerabilities—a concerning development that indicates potential supply chain risks or advanced vulnerability discovery capabilities.
## Technical Details
CVE-2026-35273 exploits insufficient input validation in PeopleSoft's web tier authentication layer. The vulnerability allows attackers to craft specially malformed HTTP requests that bypass authentication controls and inject arbitrary code into the application server.
Attack flow:
| Step | Description |
|------|-------------|
| 1. | Attacker identifies exposed PeopleSoft instance via internet scanning |
| 2. | Malicious HTTP request with crafted payload is sent to authentication endpoint |
| 3. | Insufficient input validation allows authentication bypass |
| 4. | Arbitrary code executes with application server privileges |
| 5. | Attacker establishes persistence and exfiltrates data |
Exploitation requirements:
The vulnerability resides in PeopleSoft versions 9.2.x through 9.3.x, with Oracle initially reporting that certain patch levels remain unaffected. However, researchers have noted that vulnerable instances are trivially identifiable through banner grabbing and standard reconnaissance techniques, making mass exploitation possible.
Proof-of-concept code has reportedly been shared in closed threat actor forums, accelerating exploitation velocity across less-patched environments.
## Implications for Organizations
The impact of this vulnerability extends far beyond individual PeopleSoft deployments. Organizations leveraging PeopleSoft for HR and financial management face cascading risks:
Data theft exposure:
Operational disruption:
Compliance violations:
Second-order risks:
Organizations should assume that if their PeopleSoft systems were publicly exposed or scanned during the vulnerability window, they may have already been compromised.
## Recommendations
Immediate actions (within 24 hours):
1. Identify affected systems — Audit your environment to locate all PeopleSoft instances and document their versions
2. Restrict network access — Implement firewall rules limiting PeopleSoft access to authorized networks only; disable external internet exposure if possible
3. Enable monitoring — Increase logging verbosity on PeopleSoft application and web servers to detect exploitation attempts
4. Notify security team — Escalate to incident response and threat intelligence teams
Short-term mitigation (within 1 week):
Long-term hardening:
---
## HackWire Analysis
What makes CVE-2026-35273 particularly alarming is not just its technical severity, but its exploitation timeline and distribution model. Oracle's disclosure reveals that ShinyHunter has weaponized this flaw while it remained unknown to the broader security community—suggesting either advanced vulnerability discovery capabilities or a tip from an insider source.
The timing also matters: PeopleSoft patches are notoriously difficult to deploy in enterprise environments. Most organizations operate on quarterly or semi-annual patch cycles due to testing requirements and business continuity concerns. This creates a massive window where systems remain vulnerable despite patch availability. We've observed this pattern repeatedly with enterprise software—the gap between patch release and widespread deployment can stretch to 6-12 months in large organizations, especially in regulated industries like healthcare and finance.
More critically, ShinyHunter's use of this vulnerability for mass data theft rather than targeted espionage indicates that they've industrialized their operation. They're not conducting surgical attacks; they're systematically scanning for vulnerable instances and extracting whatever sensitive data they find. This is the evolution of ransomware tactics: skip the encryption, just steal the data and monetize it through direct sales on crime forums or targeted extortion.
Organizations should not treat this as a routine patch cycle. The presence of confirmed active exploitation and the breadth of data PeopleSoft systems contain (payroll, healthcare enrollment, financial records) means this rises to CISO-level incident response status. If your organization runs PeopleSoft, you need to assume compromise unless you have forensic evidence proving otherwise.
— HackWire Editorial
---
## Related Coverage