CVE-2026-35273

PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE: stopped at runtime

Waratek RASP’s secure runtime rules stop this class of attack out of the box - no application change, no vendor patch, no downtime.

Published June 11, 2026 · Updated July 23, 2026

Blocked by secure rule CRITICAL CVSS 9.8 v3.1 Actively exploited

The vulnerability

Pre-authentication remote code execution via SSRF and Java XMLDecoder deserialization

PeopleSoft's Integration Broker publishes an unauthenticated listening connector at /PSIGW/HttpListeningConnector that will fetch whatever URL an inbound XML message names. Attackers point it back at the server itself to reach /PSEMHUB/hub, the internal-only Environment Management Hub whose only access control is an IP allow-list that a loopback request satisfies, and use the hub's OPERATION handler to plant a crafted XML file on disk. On the next web-tier restart PSEMHUB hands that file to java.beans.XMLDecoder, which instantiates the attacker's objects and executes code as the web-tier service account. Oracle's earlier serialization-filter hardening never covered the XMLDecoder path, so fully patched 8.61 and 8.62 installations were exposed. The ShinyHunters extortion group exploited it as a zero-day from May 27 to June 9, 2026, two weeks before Oracle's out-of-band alert, hitting more than 100 organizations - around two thirds of them universities and colleges.

Affected softwareOracle PeopleSoft Enterprise PeopleTools (Integration Broker and Environment Management Hub)
Affected versions8.61 and 8.62
WeaknessUnauthenticated SSRF chained to unsafe deserialization (CWE-306)
Published2026-06-11
SeverityCRITICAL · CVSS 9.8

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP applies a secure runtime rule that covers this whole class of attack out of the box - the exploit is stopped inside the JVM before it ever reaches a dangerous sink.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE FAQ

Is PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE (CVE-2026-35273) exploitable?

CVE-2026-35273 carries a CVSS 9.8/10 (CRITICAL) rating and affects Oracle PeopleSoft Enterprise PeopleTools (Integration Broker and Environment Management Hub) 8.61 and 8.62. PeopleSoft's Integration Broker publishes an unauthenticated listening connector at /PSIGW/HttpListeningConnector that will fetch whatever URL an inbound XML message names. Attackers point it back at the server itself to reach /PSEMHUB/hub, the internal-only Environment Management Hub whose only access control is an IP allow-list that a loopback request satisfies, and use the hub's OPERATION handler to plant a crafted XML file on disk. On the next web-tier restart PSEMHUB hands that file to java.beans.XMLDecoder, which instantiates the attacker's objects and executes code as the web-tier service account. Oracle's earlier serialization-filter hardening never covered the XMLDecoder path, so fully patched 8.61 and 8.62 installations were exposed. The ShinyHunters extortion group exploited it as a zero-day from May 27 to June 9, 2026, two weeks before Oracle's out-of-band alert, hitting more than 100 organizations - around two thirds of them universities and colleges. It is listed in CISA's Known Exploited Vulnerabilities catalog, with known ransomware campaign use.

How does Waratek mitigate PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE (CVE-2026-35273)?

Waratek RASP blocks exploitation of PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE (CVE-2026-35273) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE (CVE-2026-35273) exploited after disclosure?

A working exploit for CVE-2026-35273 appeared within 2 days of its NVD disclosure, on June 12, 2026.

Protect your apps in production

Get protected against PeopleSoft PeopleTools PSEMHUB Pre-Auth RCE - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2026-35273 and attacks like it, and get you covered in production.