PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61077 Oracle Corporation CVE debrief

The CVE-2026-61077 record indicates a difficult-to-exploit vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, allowing low-privileged attackers with logon access to compromise the system, potentially impacting additional products. This high-severity vulnerability has a CVSS score of 7.5 and can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data. Organizations using PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, especially those with low-privileged users with logon access, should be aware of this vulnerability and take steps to mitigate it. The vulnerability is difficult to exploit, but successful attacks can have significant impacts.

Vendor
Oracle Corporation
Product
PeopleSoft Enterprise SCM Mobile Inventory Management
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-06
Advisory published
2026-07-21
Advisory updated
2026-08-06

Who should care

Organizations using PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, especially those with low-privileged users with logon access, should be aware of this vulnerability and take steps to mitigate it.

Technical summary

CVE-2026-61077 is a high-severity vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, with a CVSS score of 7.5. It allows low-privileged attackers with logon access to compromise the system, potentially impacting additional products. The vulnerability is difficult to exploit, but successful attacks can result in unauthorized data access, creation, deletion, or modification. This vulnerability affects PeopleSoft Enterprise SCM Mobile Inventory Management 9.2 and has a significant impact on additional products. The CVSS vector is (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). The vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, and attacks may significantly impact additional products (scope change). To address this vulnerability, it is essential to understand the affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review, and exceptions should be tracked, and remediated assets should be retested, with the item only closed after evidence is documented. The PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security) is affected, and the supported version that is affected is 9.2. The vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile Inventory Management executes to compromise PeopleSoft Enterprise SCM Mobile Inventory Management. While the vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management 9.2

Defensive priority

Organizations using PeopleSoft Enterprise SCM Mobile Inventory Management 9.2 should prioritize patching due to the high CVSS score of 7.5 and potential for significant impact on additional products.

Recommended defensive actions

  • Apply patches or updates provided by Oracle for PeopleSoft Enterprise SCM Mobile Inventory Management 9.2.
  • Implement compensating controls, such as monitoring and access restrictions, until patching can be performed.
  • Conduct inventory checks to identify and prioritize affected systems.
  • Review and update incident response plans to address potential impacts on additional products.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE-2026-61077 record indicates a difficult-to-exploit vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, allowing low-privileged attackers with logon access to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all accessible data.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:38.523Z and has not been modified since then.