SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61059 2026-07-21

CVE-2026-61059: Critical Unauthenticated Flaw in Oracle PeopleSoft SCM Order Management

"A critical, network-exploitable vulnerability in Oracle PeopleSoft Enterprise SCM Order Management (version 9.2) lets unauthenticated attackers read and alter sensitive data over HTTP, carrying a CVSS 3.1 base score of…"

A critical, network-exploitable vulnerability in Oracle PeopleSoft Enterprise SCM Order Management (version 9.2) lets unauthenticated attackers read and alter sensitive data over HTTP, carrying a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-61059 is a vulnerability in the Security component of Oracle's PeopleSoft Enterprise SCM Order Management product. Per Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. No privileges and no user interaction are required, as reflected in its CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all data accessible to PeopleSoft Enterprise SCM Order Management, as well as unauthorized read access up to complete access of all accessible data. The confidentiality and integrity impacts are both rated HIGH; availability is not affected. With an attack vector of network, low complexity, and no authentication needed, the barrier to exploitation is minimal, driving the 9.1 CRITICAL score.

What's Vulnerable

Patch Status

Oracle addressed this issue as part of its July 2026 Critical Patch Update (cpujul2026). Organizations running PeopleSoft Enterprise SCM Order Management 9.2 should apply the fixes from the July 2026 CPU. No CISA KEV entry was supplied, so active exploitation is not confirmed by KEV in this source material; nonetheless, the low exploitation barrier and critical severity warrant prompt patching.

Sources