Junglewise Threat Intelligence

CVE-2026-61086: Oracle PeopleSoft Enterprise SCM Order Management information disclosure

CVE-2026-61086 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle PeopleSoft Enterprise SCM Order Management. Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise SCM Order Management, a software suite used by large organizations to manage supply chains and customer orders, contains a security vulnerability in its security component. An unauthorized person can exploit this flaw over the internet to gain access to sensitive business data. This could lead to the exposure of critical proprietary information or a complete breach of all data managed within the Order Management system.

Technical details

A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Order Management version 9.2. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTPS to compromise the system. Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by the SCM Order Management module. The vulnerability has a CVSS 3.1 base score of 7.5, primarily impacting confidentiality. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise SCM Order Management 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References

Related threats