Sceawere
Vulnerability Detail
CVE-2026-61207Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft eProcurement Unauthorized Data Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise SCM eProcurement
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. While the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. While the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-07-21T22:18:52.447Z",
"pubdate": "2026-07-21T22:18:52.447Z",
"executiveSummary": "This vulnerability resides in the Manage Requisition Status component of Oracle PeopleSoft Enterprise SCM eProcurement version 9.2.\nThe security flaw is classified as a critical-severity vulnerability due to its potential for unauthorized access to sensitive information and unauthorized manipulation of system data.\nThe vulnerability allows an unauthenticated, remote attacker to gain access over a network via HTTP, bypassing standard security authentication controls.\nA significant risk factor is the change in scope (S:C), indicating that successful exploitation could compromise systems or data beyond the immediate eProcurement module, potentially affecting the broader PeopleSoft ecosystem.\nThe impact is characterized by high confidentiality loss and partial integrity compromise, meaning attackers can read, modify, or delete critical enterprise data.\nGiven the lack of required user interaction or prior authentication, the attack complexity is considered low, presenting an immediate threat to the confidentiality and integrity of enterprise resource planning environments.",
"technicalDetails": "The vulnerability exists within the Manage Requisition Status component of PeopleSoft Enterprise SCM eProcurement version 9.2, which fails to adequately enforce authorization checks for incoming HTTP requests.\nThe root cause is a deficiency in input validation and access control enforcement, which allows remote actors to interact with the underlying business logic without possessing valid credentials.\nBecause the vulnerability is reachable over a network via standard HTTP protocols without requiring prior authentication or user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N), it is categorized as a high-exposure entry point for unauthorized actors.\nThe scope change (S:C) attribute is critical; it implies that the application's processing of untrusted requests allows an attacker to execute operations that traverse beyond the restricted context of the eProcurement module, potentially leveraging the application's service account to reach integrated back-end databases or external application interfaces.\nExploitation involves an attacker crafting malicious HTTP requests directed at the vulnerable component. By bypassing the authentication filter, the attacker can submit requests to function names responsible for retrieving or modifying requisition status data.\nThe payload behavior is twofold: first, the attacker gains unauthorized read access to sensitive records (Confidentiality impact: H). Second, the attacker gains sufficient privileges to perform unauthorized write operations, allowing for the unauthorized update, insertion, or deletion of records within the eProcurement database (Integrity impact: L).\nStep-by-step execution: (1) The attacker initiates a connection to the PeopleSoft Enterprise SCM eProcurement HTTP endpoint. (2) The attacker sends a specially crafted request targeted at the Manage Requisition Status component. (3) The application, failing to validate the request's origin or authentication state, grants access to the underlying business functions. (4) The attacker proceeds to interact with the data layer, extracting sensitive requisition information or injecting malicious changes to existing records.\nThis behavior results in a complete compromise of data held within the affected component, potentially leading to unauthorized procurement actions or disclosure of supply chain intelligence."
}