Junglewise Threat Intelligence

CVE-2026-61089: Oracle PeopleSoft Enterprise SCM Inventory security bypass

CVE-2026-61089 · Severity: high · CVSS 8.2 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise SCM Inventory, a software suite used for managing supply chain and warehouse operations, contains a security vulnerability. An unauthorized person can access the system over the internet without needing a username or password. This could allow them to view sensitive business data or modify inventory records, potentially disrupting supply chain operations and compromising data integrity.

Technical details

A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Inventory version 9.2. The flaw is categorized as easily exploitable and allows an unauthenticated attacker to gain network access via HTTP. An attacker can achieve unauthorized read access to all accessible data (high confidentiality impact) and unauthorized update, insert, or delete access to a subset of data (low integrity impact). The vulnerability does not require user interaction and has no impact on system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise SCM Inventory 9.2

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61089
  • 2026-07-21: advisory: Oracle released security alert cpujul2026.html

References

Related threats