← Back to Feed
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
June 18, 2026 · Trend Micro · Severity: MEDIUM
A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools abuses the Integration Broker's PSIGW gateway to execute code inside the application server's Java virtual machine (JVM), evading behavioral and network sensors.
Key Takeaways
- Trend Micro disclosed a pre-authentication remote code execution chain in Oracle PeopleSoft PeopleTools that abuses the Integration Broker's PSIGW gateway.
- The attack executes code inside the application server's Java virtual machine, evading behavioral and network sensors during the intrusion.
- Organizations running PeopleSoft PeopleTools should prioritize patching the PSIGW SSRF chain and monitor for exploitation of the Integration Broker.