Description
Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Inventory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Inventory 9.2. An unauthenticated attacker who can reach the application over HTTPS can exploit this flaw to bypass authentication and read any data that the application can serve. The weakness reflects improper authorization (CWE‑284) and results in a confidentiality compromise without affecting integrity or availability.

Affected Systems

Oracle PeopleSoft Enterprise SCM Inventory version 9.2 is affected; no other versions are listed as impacted in the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates medium‑high severity, largely due to impact on confidentiality. The EPSS score is less than 1%, showing that real‑world exploitation is currently rare and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can be triggered remotely over HTTPS without authentication, the risk to organizations with network exposure is moderate and requires prompt action.

Generated by OpenCVE AI on August 4, 2026 at 01:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft Security Patch for Enterprise SCM Inventory 9.2 from the July 2026 CPU advisory (https://www.oracle.com/security-alerts/cpujul2026.html).
  • Restrict external HTTPS access to the PeopleSoft SCM Inventory web server to trusted internal networks or VPN connections so that unauthenticated users cannot reach the vulnerable interface.
  • Enable audit logging for all authentication attempts and data access requests, and monitor the logs for anomalous or unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Vulnerability in Oracle PeopleSoft Enterprise SCM Inventory 9.2

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Vulnerability in Oracle PeopleSoft Enterprise SCM Inventory 9.2

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Allows Full Data Exposure in PeopleSoft SCM Inventory 9.2

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Allows Full Data Exposure in PeopleSoft SCM Inventory 9.2

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Inventory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Inventory
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_inventory:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Inventory
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Inventory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:13:25.627Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61085

cve-icon Vulnrichment

Updated: 2026-07-23T19:13:13.588Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses