Description
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Purchasing accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle PeopleSoft Enterprise SCM Purchasing allows an attacker with network access to perform unauthorized creations, deletions, or modifications of data, as well as read access to restricted data. The vulnerability exploits insufficient access control, leading to potential loss of data integrity and confidentiality. The impact is confined to the Purchasing component of the PeopleSoft suite and does not affect overall system availability. The weakness is identified as CWE-284, which pertains to improper authorization controls.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise SCM Purchasing version 9.2 is vulnerable. Attackers can exploit this issue only when the affected component is exposed to public or untrusted networks via HTTP. Users of newer versions or those that do not run the Purchasing module are not impacted.

Risk and Exploitability

The CVSS v3.1 base score of 8.2 reflects the high risk of exploitation, primarily due to the lack of authentication required. The EPSS score of less than 1% indicates that, at present, the probability of active exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. However, the mode of operation – an unauthenticated attacker using a simple HTTP request – makes it trivially exploitable by a broad attacker population, emphasizing the importance of remediating this weakness promptly.

Generated by OpenCVE AI on August 4, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE‑2026‑61205 for PeopleSoft Enterprise SCM Purchasing 9.2.
  • Configure network firewall rules to restrict HTTP access to the Purchasing component to trusted IP addresses only.
  • Review and tighten database and application permissions to enforce least privilege, ensuring no account can perform unauthorized write or read operations on sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification in Oracle PeopleSoft Enterprise SCM Purchasing

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification in Oracle PeopleSoft Enterprise SCM Purchasing

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification of Oracle PeopleSoft Enterprise SCM Purchasing Data

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification of Oracle PeopleSoft Enterprise SCM Purchasing Data

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Purchasing accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Purchasing
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_purchasing:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Purchasing
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Purchasing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-05T14:17:11.006Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61205

cve-icon Vulnrichment

Updated: 2026-07-22T19:27:44.831Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses