Cyber Posture

CVE-2026-34309

High

Published: 21 April 2026

Published
21 April 2026
Modified
24 April 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0005 15.4th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-34309 is a high-severity Improper Access Control (CWE-284) vulnerability in Oracle Peoplesoft Enterprise Peopletools. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 15.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly mitigates CVE-2026-34309 by requiring timely patching of the specific flaw in PeopleSoft Enterprise PeopleTools as advised in the Oracle Critical Patch Update.

prevent

Enforces approved authorizations to prevent low-privileged attackers from gaining unauthorized create, delete, modify, or read access to critical PeopleTools data via improper access control.

prevent

Limits damage from low-privileged exploitation by ensuring accounts have only necessary privileges, reducing the scope of unauthorized data access and modification.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Vulnerability is an improper access control flaw in a network-accessible (HTTP) web component of PeopleSoft, allowing low-privileged authenticated attackers to perform unauthorized data access and modification; directly enables exploitation of public-facing applications (T1190) and privilege escalation via software vulnerability (T1068).

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this…

more

vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Deeper analysisAI

CVE-2026-34309 is a vulnerability in the Security component of Oracle PeopleSoft Enterprise PeopleTools, part of the Oracle PeopleSoft product. Affected versions include 8.61 through 8.62. Classified under CWE-284 (Improper Access Control), it carries a CVSS 3.1 base score of 8.1 (vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N), with high impacts to confidentiality and integrity but no availability impact. The issue was published on April 21, 2026.

A low-privileged attacker with network access via HTTP can easily exploit this vulnerability to compromise PeopleSoft Enterprise PeopleTools. Successful exploitation enables unauthorized creation, deletion, or modification of critical data or all accessible PeopleTools data, as well as unauthorized access to critical data or complete access to all PeopleTools accessible data.

For mitigation details, refer to the Oracle Critical Patch Update advisory at https://www.oracle.com/security-alerts/cpuapr2026.html.

Details

CWE(s)

Affected Products

oracle
peoplesoft enterprise peopletools
8.61, 8.62

CVEs Like This One

CVE-2025-21545Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2026-22011Same vendor: Oracle
CVE-2025-50105Same vendor: Oracle
CVE-2026-34287Same vendor: Oracle
CVE-2026-35242Same vendor: Oracle
CVE-2026-21962Same vendor: Oracle
CVE-2026-35251Same vendor: Oracle
CVE-2025-50060Same vendor: Oracle
CVE-2026-21994Same vendor: Oracle
CVE-2026-21997Same vendor: Oracle

References