Oracle PeopleSoft PeopleTools zero-day RCE [CVE-2026-35273]
June 12, 2026
Deskripsi
1
| |
|
|
| |
Oracle mengumumkan pada 10 Juni 2026 kerentanan kritis CVE-2026-35273 pada Oracle PeopleSoft PeopleTools yang memungkinkan unauthenticated remote code execution melalui komponen Updates Environment Management. Aktivitas eksploitasi diamati setidaknya pada 27 Mei–9 Juni 2026 dan dikaitkan dengan kampanye data theft/extortion oleh UNC6240 (ShinyHunters). Severity: High (oracle.com)
|
|
| |
|
|
Metode Serangan
2
| |
|
|
| |
Penyerang mengirim crafted HTTP request tanpa autentikasi ke endpoint Environment Management Hub seperti /PSEMHUB/* dan /PSIGW/HttpListeningConnector untuk memperoleh RCE/takeover pada PeopleTools, lalu dapat memasang webshell atau MeshCentral agent, melakukan reconnaissance, lateral movement, dan mencuri data untuk extortion. (oracle.com)
|
|
| |
|
|
Sistem Terdampak
3
| |
|
|
| |
Oracle PeopleSoft Enterprise PeopleTools versi 8.61 dan 8.62; Oracle juga menyatakan pelanggan Oracle PeopleSoft Enterprise Applications dapat ikut terdampak, dan versi lama yang sudah unsupported kemungkinan juga rentan. (oracle.com)
|
|
| |
|
|
Mitigasi
4
| |
|
|
| |
- Segera terapkan emergency mitigation/patch dari Oracle dan pastikan sistem berada pada versi yang masih supported. (oracle.com)
- Disable EMHub Service pada Multi-Server atau hapus aplikasi PSEMHUB pada Single-Server; bila belum bisa, blok akses eksternal ke /PSEMHUB/* dan /PSIGW/HttpListeningConnector di firewall/perimeter. (cloud.google.com)
- Review PIA WebLogic access log untuk POST /PSEMHUB/hub dan POST /PSIGW/HttpListeningConnector, lalu periksa file .jsp tidak sah di PSEMHUB.war, direktori mencurigakan, serta trafik outbound SMB ke tujuan eksternal yang tidak tepercaya. (cloud.google.com)
|
|
| |
|
|
Referensi: ?
1. https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
2. https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
3. https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ (oracle.com)