Description
Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile Inventory Management executes to compromise PeopleSoft Enterprise SCM Mobile Inventory Management. While the vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle PeopleSoft Enterprise SCM Mobile Inventory Management version 9.2. An attacker who already has local access to the infrastructure can exploit this flaw to compromise the application. Exploitation allows them to create, delete, or modify critical data, and to obtain unauthorized read access to any data the application processes. Because the fault changes the scope of the application, a successful attack may also impact other PeopleSoft components that share the same environment.

Affected Systems

Affected systems are Oracle Corporation’s PeopleSoft Enterprise SCM Mobile Inventory Management product, specifically release 9.2. No other versions or products are listed as affected in the available data.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 7.5, with low attack vector (local), high attack complexity, low privilege requirement, and no user interaction, resulting in confidentiality and integrity impact while availability remains unaffected. The EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation. The issue is not currently listed in CISA’s KEV catalog. The likely attack path requires a threat actor to first achieve local log‑on privileges on the host running PeopleSoft, then use the application’s insecure access control logic to elevate their reach within the data set.

Generated by OpenCVE AI on August 4, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security advisories for PeopleSoft Enterprise SCM Mobile Inventory Management 9.2 to determine if a patch or update is available and apply it as soon as possible.
  • If no patch is available, consider upgrading to a newer supported release and verify that all known security updates have been applied.
  • Limit local user accounts that have access to the PeopleSoft server; enforce least‑privilege and remove unused accounts.
  • Continuously monitor system logs for suspicious activity related to unauthorized data access or modification attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Access Exploitation Allows Unauthorized Data Modification in PeopleSoft Mobile Inventory Management

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile Inventory Management executes to compromise PeopleSoft Enterprise SCM Mobile Inventory Management. While the vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Mobile Inventory Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_mobile_inventory_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Mobile Inventory Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Mobile Inventory Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:06:48.805Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61077

cve-icon Vulnrichment

Updated: 2026-07-24T14:06:43.728Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:38.523

Modified: 2026-08-06T15:02:48.110

Link: CVE-2026-61077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses