Sceawere

Vulnerability Detail

CVE-2026-61059Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Order Management Unauthorized Access

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise SCM Order Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:36.620Z",
  "pubdate": "2026-07-21T22:18:36.620Z",
  "executiveSummary": "This vulnerability affects Oracle PeopleSoft Enterprise SCM Order Management version 9.2, specifically within its security component. The flaw allows an unauthenticated, remote attacker to gain unauthorized access to the system via HTTP.\nThe vulnerability is characterized by a critical security deficiency that enables full read and write access to sensitive data within the Order Management module. This bypasses standard authentication and authorization controls, potentially leading to widespread data compromise or manipulation.\nWith a CVSS 3.1 base score of 9.1, this represents a severe risk to organizational confidentiality and integrity. The vulnerability is highly exploitable, requiring no prior authentication or user interaction. Given that the attack vector is network-based, any system with HTTP access to the PeopleSoft environment is potentially at risk.\nImpact includes the ability for an adversary to modify or delete critical business data, resulting in significant operational disruption and data integrity loss. Immediate attention is required to secure the environment.",
  "technicalDetails": "The vulnerability resides within the Security component of the PeopleSoft Enterprise SCM Order Management module, version 9.2. It represents a significant failure in the application's authentication and authorization enforcement mechanisms, allowing requests to proceed without validating the requester's identity or permissions.\nThe attack vector is identified as network-based, utilizing the HTTP protocol. Because the vulnerability does not require authentication or user interaction, an attacker can craft malicious HTTP requests directed at the vulnerable component. The ease of exploitation is high, as the system does not require specialized conditions or high-level privileges to facilitate the attack.\nUpon receiving a crafted HTTP request, the vulnerable Security component fails to properly verify the session or the authorization context of the incoming call. This omission allows an unauthenticated actor to interact with application functions that should be restricted. An attacker can leverage this access to perform unauthorized operations against the underlying data structures of the Order Management system.\nThe exploitation flow is as follows: 1) The attacker identifies a target instance of PeopleSoft SCM Order Management 9.2 accessible over the network. 2) The attacker transmits a specifically crafted HTTP request designed to interact with the Order Management security logic. 3) Due to the lack of input validation and authentication checks, the system processes the request as if it were a legitimate, authorized call. 4) The application executes the requested operations, which may include querying, modifying, or deleting sensitive records.\nPost-exploitation, the impact is severe. An attacker can perform a full dump of sensitive data, leading to a loss of confidentiality. Furthermore, by modifying or deleting records, the attacker directly impacts the integrity of business operations. The scope of this vulnerability remains limited to the PeopleSoft Enterprise SCM Order Management product, but the level of unauthorized access constitutes a total compromise of data within that specific component."
}
CVE-2026-61059: PeopleSoft Order Management Unauthorized Access (CRITICAL Severity, CVSS: 9.1) - Sceawere