Junglewise Threat Intelligence

CVE-2026-61059: Oracle PeopleSoft Enterprise SCM Order Management security bypass

CVE-2026-61059 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise SCM Order Management. Vendors: Oracle.

Executive brief

A critical security vulnerability has been identified in Oracle PeopleSoft Enterprise SCM Order Management, a tool used by organizations to manage supply chain and sales orders. An unauthorized attacker could exploit this flaw over the network to gain full access to sensitive business data without needing a username or password. This could lead to the unauthorized viewing, modification, or deletion of critical supply chain records and customer information.

Technical details

A vulnerability in the Security component of Oracle PeopleSoft Enterprise SCM Order Management (version 9.2) allows for an unauthenticated compromise via HTTP. The flaw is classified as easily exploitable, requiring no user interaction or special privileges. An attacker with network access can achieve high confidentiality and integrity impacts, effectively gaining complete unauthorized access to or control over all data managed by the affected component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle PeopleSoft Enterprise SCM Order Management 9.2

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats