Security & Threat Intelligence · 06.07.2026, 18:04 UTC
ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability
| Schweregrad | critical aktiv ausgenutzt (KEV) |
|---|---|
| CVSS | 9.3 |
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Zero Day Initiative ↗ |
| Veröffentlicht | 06.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad kritisch (CVSS 9.3). Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2026-35273. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.