A critical, network-exploitable vulnerability in Oracle PeopleSoft Enterprise SCM Order Management (version 9.2) lets unauthenticated attackers read and alter sensitive data over HTTP, carrying a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-61059 is a vulnerability in the Security component of Oracle's PeopleSoft Enterprise SCM Order Management product. Per Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. No privileges and no user interaction are required, as reflected in its CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all data accessible to PeopleSoft Enterprise SCM Order Management, as well as unauthorized read access up to complete access of all accessible data. The confidentiality and integrity impacts are both rated HIGH; availability is not affected. With an attack vector of network, low complexity, and no authentication needed, the barrier to exploitation is minimal, driving the 9.1 CRITICAL score.
What's Vulnerable
- Product: Oracle PeopleSoft Enterprise SCM Order Management
- Component: Security
- Affected version: 9.2 (the supported version listed as affected)
Patch Status
Oracle addressed this issue as part of its July 2026 Critical Patch Update (cpujul2026). Organizations running PeopleSoft Enterprise SCM Order Management 9.2 should apply the fixes from the July 2026 CPU. No CISA KEV entry was supplied, so active exploitation is not confirmed by KEV in this source material; nonetheless, the low exploitation barrier and critical severity warrant prompt patching.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61059, https://nvd.nist.gov/vuln/detail/CVE-2026-61059