Description
Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Inventory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle PeopleSoft Enterprise SCM Inventory is an improper access control flaw (CWE‑284). An unauthenticated attacker can send HTTP requests that result in unauthorized access to sensitive data and the ability to update or delete that data. The flaw causes significant confidentiality damage and a moderate integrity impact, as reflected by the CVSS 3.1 Base Score of 8.2. The attack does not require user interaction and can be performed from any network location that can reach the HTTP interface, making remote compromise possible.

Affected Systems

Oracle Corporation PeopleSoft Enterprise SCM Inventory version 9.2 is affected. No other versions or products are listed as vulnerable.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability, and the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. Since the flaw is not listed in CISA KEV, there is no current evidence of widespread exploitation. The attack vector is inferred to be remote via unauthenticated HTTP traffic, and successful exploitation would allow the attacker to read or modify accessible data.

Generated by OpenCVE AI on August 4, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle PeopleSoft Enterprise SCM Inventory 9.2 security patch that fixes CVE-2026-61089.
  • Limit inbound traffic to the PeopleSoft HTTP interface to trusted IP ranges or via a corporate VPN or firewall.
  • Enforce mandatory authentication, HTTPS, and least privilege for all PeopleSoft users, and audit privileges regularly.

Generated by OpenCVE AI on August 4, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle PeopleSoft SCM Inventory 9.2 Enables Data Compromise and Unauthorized Modification

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle PeopleSoft SCM Inventory 9.2 Enables Data Compromise and Unauthorized Modification

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification in PeopleSoft Enterprise SCM Inventory
Weaknesses CWE-200

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification in PeopleSoft Enterprise SCM Inventory
Weaknesses CWE-200

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Inventory. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Inventory
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_inventory:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Inventory
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Inventory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:02:13.360Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61089

cve-icon Vulnrichment

Updated: 2026-07-24T14:02:08.656Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses