<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Missing-Authentication on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/missing-authentication/</link><description>Recent content in Missing-Authentication on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 12 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/missing-authentication/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-35273: Oracle PeopleSoft Auth Bypass Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-35273-oracle-peoplesoft-peopletools-missing-authentication-takeover/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-35273-oracle-peoplesoft-peopletools-missing-authentication-takeover/</guid><description>CVE-2026-35273 is a critical Oracle PeopleSoft PeopleTools missing authentication flaw enabling full system takeover. Patch by 15 June 2026.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities</a></p>
<hr>
<p>A critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker to take full control of the system due to a missing authentication check on a critical function. This flaw requires no credentials to exploit, making it particularly dangerous for any internet-facing or internally accessible PeopleSoft deployment. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Immediately apply Oracle&rsquo;s patch or mitigation guidance, and in the interim restrict network access to PeopleSoft PeopleTools interfaces via firewall rules or VPN — ensuring the application is not exposed to untrusted networks. Audit your environment for any signs of unauthorised access or anomalous activity in PeopleSoft logs since exposure without authentication controls is high-impact.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CVE-2026-35273: Oracle  PeopleSoft Enterprise PeopleTools</a></p>
]]></content:encoded></item></channel></rss>