Junglewise Threat Intelligence

CVE-2026-61205: Oracle PeopleSoft Enterprise SCM Purchasing data manipulation vulnerability

CVE-2026-61205 · Severity: high · CVSS 8.2 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle PeopleSoft Enterprise SCM Purchasing, a software suite used by organizations to manage supply chain procurement and vendor relationships, contains a high-severity vulnerability. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive purchasing data. This could result in the unauthorized creation, deletion, or modification of critical business records, potentially disrupting supply chain operations and compromising financial integrity.

Technical details

A vulnerability in the Purchasing component of Oracle PeopleSoft Enterprise SCM Purchasing (version 9.2) allows for unauthorized data manipulation. The flaw is categorized as easily exploitable, requiring no authentication or user interaction, and is reachable via the HTTP protocol. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of the application's data. The vulnerability has a CVSS 3.1 base score of 8.2, primarily impacting data integrity and confidentiality. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise SCM Purchasing 9.2

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61205 by Oracle.
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released.

References