PatchSiren cyber security CVE debrief
CVE-2026-61207 Oracle Corporation CVE debrief
A critical vulnerability was discovered in PeopleSoft Enterprise SCM eProcurement, specifically in the Manage Requisition Status component. The vulnerability has a CVSS score of 9.3 and can allow unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data, as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. Organizations should prioritize patching this vulnerability to prevent potential attacks. The vulnerability is easily exploitable and has a high impact on confidentiality and integrity.
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise SCM eProcurement
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-12
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-12
Who should care
Organizations using PeopleSoft Enterprise SCM eProcurement should prioritize patching this vulnerability to prevent potential attacks. The vulnerability has a high CVSS score and can allow unauthenticated attackers to compromise the system. Security teams and vulnerability management teams should review the affected scope and severity to determine the necessary actions. Operators and platform administrators should also be aware of the vulnerability and take necessary precautions.
Technical summary
The vulnerability is located in the Manage Requisition Status component of PeopleSoft Enterprise SCM eProcurement. It has a CVSS score of 9.3 and can allow unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data, as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. The vulnerability is easily exploitable and has a high impact on confidentiality and integrity.
Defensive priority
High
Recommended defensive actions
- Apply the patch provided by the vendor
- Conduct a thorough inventory check to identify affected systems
- Implement compensating controls to monitor and detect potential attacks
- Restrict access to the affected component
- Monitor for suspicious activity
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-21T22:18:52.447Z and was last modified on 2026-07-22T19:17:08.430Z. The NVD entry is currently under review. The vulnerability affects PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft, specifically the Manage Requisition Status component. The CVSS score of 9.3 indicates a critical vulnerability. The evidence provided is limited, and further verification is needed to confirm the affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61207 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61207
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61207 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61207
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.