Description
Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. While the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Manage Requisition Status component of PeopleSoft Enterprise SCM eProcurement. An attacker who can reach the application via standard HTTP does not need to authenticate and can obtain unauthorized access to critical data and can also update, insert, or delete data that is normally protected. The flaw is a full authorization bypass that brings confidentiality to a high level and a moderate integrity impact, as reflected in the CVSS score of 9.3.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise SCM eProcurement version 9.2 is affected. Other Oracle PeopleSoft products that interact closely with eProcurement may also be impacted due to a scope change, but no other specific versions are listed.

Risk and Exploitability

The CVSS score of 9.3 categorizes this vulnerability as Critical. The EPSS score of less than 1% indicates that exploitation is considered unlikely at present, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the attack vector is a straightforward HTTP request to the exposed component, and because no authentication is required, the risk to an organization that exposes the service to the public or an untrusted network is high.

Generated by OpenCVE AI on August 4, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft update that addresses CVE-2026-61207 as published in the Oracle CPU July 2026 advisory
  • Restrict network access to the PeopleSoft Enterprise SCM eProcurement HTTP endpoint by configuring firewalls, VPNs, or IP whitelisting so that only trusted IP addresses can reach the service
  • Enable comprehensive logging and monitoring for authentication attempts, data access, and change operations within PeopleSoft, and enforce strict access control policies on critical data

Generated by OpenCVE AI on August 4, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification via PeopleSoft eProcurement

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification via PeopleSoft eProcurement

Mon, 27 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Data Control in Oracle PeopleSoft eProcurement

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Data Control in Oracle PeopleSoft eProcurement

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. While the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Eprocurement
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_eprocurement:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Eprocurement
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Eprocurement
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:27:39.491Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61207

cve-icon Vulnrichment

Updated: 2026-07-22T18:27:32.773Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses