Junglewise Threat Intelligence

CVE-2026-61207: Oracle PeopleSoft Enterprise SCM eProcurement data breach in Manage Requisition Status

CVE-2026-61207 · Severity: critical · CVSS 9.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle PeopleSoft's eProcurement system, which manages corporate purchasing and requisition workflows. An unauthenticated attacker can remotely access the system to view sensitive business data or modify records without authorization. This could lead to the exposure of confidential procurement information or the disruption of supply chain operations.

Technical details

A vulnerability in the Manage Requisition Status component of Oracle PeopleSoft Enterprise SCM eProcurement version 9.2 allows unauthenticated attackers with network access via HTTP to compromise the system. The flaw is characterized by a CVSS 3.1 score of 9.3, indicating high confidentiality impact and low integrity impact with a scope change, meaning the exploit can affect components beyond the immediate application. Attackers can achieve unauthorized access to all accessible data or perform unauthorized updates, inserts, or deletions of certain records. No user interaction or privileges are required for exploitation.

Affected products

  • Oracle PeopleSoft Enterprise SCM eProcurement 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update.
  • 2026-07-21: advisory

References