PatchSiren cyber security CVE debrief
CVE-2026-61077 Oracle Corporation CVE debrief
The CVE-2026-61077 record indicates a difficult-to-exploit vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, allowing low-privileged attackers with logon access to compromise the system, potentially impacting additional products. This high-severity vulnerability has a CVSS score of 7.5 and can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data. Organizations using PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, especially those with low-privileged users with logon access, should be aware of this vulnerability and take steps to mitigate it. The vulnerability is difficult to exploit, but successful attacks can have significant impacts.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise SCM Mobile Inventory Management
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Organizations using PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, especially those with low-privileged users with logon access, should be aware of this vulnerability and take steps to mitigate it.
Technical summary
CVE-2026-61077 is a high-severity vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, with a CVSS score of 7.5. It allows low-privileged attackers with logon access to compromise the system, potentially impacting additional products. The vulnerability is difficult to exploit, but successful attacks can result in unauthorized data access, creation, deletion, or modification. This vulnerability affects PeopleSoft Enterprise SCM Mobile Inventory Management 9.2 and has a significant impact on additional products. The CVSS vector is (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). The vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, and attacks may significantly impact additional products (scope change). To address this vulnerability, it is essential to understand the affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review, and exceptions should be tracked, and remediated assets should be retested, with the item only closed after evidence is documented. The PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security) is affected, and the supported version that is affected is 9.2. The vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile Inventory Management executes to compromise PeopleSoft Enterprise SCM Mobile Inventory Management. While the vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management 9.2
Defensive priority
Organizations using PeopleSoft Enterprise SCM Mobile Inventory Management 9.2 should prioritize patching due to the high CVSS score of 7.5 and potential for significant impact on additional products.
Recommended defensive actions
- Apply patches or updates provided by Oracle for PeopleSoft Enterprise SCM Mobile Inventory Management 9.2.
- Implement compensating controls, such as monitoring and access restrictions, until patching can be performed.
- Conduct inventory checks to identify and prioritize affected systems.
- Review and update incident response plans to address potential impacts on additional products.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE-2026-61077 record indicates a difficult-to-exploit vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management 9.2, allowing low-privileged attackers with logon access to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all accessible data.
Official resources
-
CVE-2026-61077 CVE record
CVE.org
-
CVE-2026-61077 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:38.523Z and has not been modified since then.