Junglewise Threat Intelligence

CVE-2026-61077: Oracle PeopleSoft Enterprise SCM Mobile Inventory Management security bypass

CVE-2026-61077 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle's PeopleSoft Enterprise SCM Mobile Inventory Management, a tool used by organizations to manage supply chain and inventory operations. A low-privileged user with access to the underlying system could exploit this flaw to gain unauthorized access to sensitive business data or modify critical inventory records. This could lead to significant data integrity issues and potentially impact other connected business systems.

Technical details

This vulnerability exists in the Security component of PeopleSoft Enterprise SCM Mobile Inventory Management version 9.2. It is classified as a local attack (AV:L) requiring low privileges (PR:L) but high complexity (AC:H) to execute. The vulnerability involves a scope change (S:C), meaning a successful exploit can impact resources beyond the security scope of the affected component. Attackers can achieve unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the application. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle PeopleSoft Enterprise SCM Mobile Inventory Management 9.2

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
  • 2026-07-21: disclosed: CVE-2026-61077 was publicly released.

References