Blog
Analysis of CVE-2026-35273: Oracle PeopleSoft PeopleTools Server Side Request Forgery
By Marcos Accossatto on Mon, 06/29/2026
CVE-2026-35273 is a serious vulnerability affecting Oracle PeopleSoft PeopleTools. It involves a server-side request forgery weakness that allows an attacker to make the PeopleSoft system send requests internally, including to sensitive components that are not normally exposed to outside users.The still active exploitation from UNC6240 (ShinyHunters) (as stated by Mandiant and Google Threat...