Summary
CVE-2026-61085 is a high-severity Improper Access Control (CWE-284) vulnerability affecting Oracle PeopleSoft Enterprise SCM Inventory version 9.2. An unauthenticated remote attacker can exploit the flaw over HTTPS — with no credentials and no user interaction required — to gain unauthorized access to sensitive data or achieve complete exposure of all accessible SCM Inventory information. The CVSS v3.1 base score is 7.5 (HIGH).
Technical details
- Root cause: Improper access control in the Security component of Oracle PeopleSoft Enterprise SCM Inventory 9.2, allowing requests to reach protected inventory data without authentication.
- Trigger conditions: The attacker needs only network access to the PeopleSoft web interface over HTTPS; no credentials, no privileges, and no victim interaction are required.
- Attack vector: Network (HTTPS); attack complexity is Low, making exploitation straightforward for any attacker who can reach an exposed instance.
- Impact: Complete confidentiality compromise of SCM Inventory data — an attacker can access sensitive or all accessible inventory records. There is no integrity or availability impact per the CVSS assessment.
Affected software
- Oracle PeopleSoft Enterprise SCM Inventory version 9.2
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for July 2026, which contains the fix for CVE-2026-61085. Refer to the Oracle CPU July 2026 advisory for patch availability and instructions specific to your PeopleSoft deployment.
- Network mitigation (if patching is not immediately possible): Restrict network access to PeopleSoft SCM Inventory interfaces so that only authorized users and IP ranges can reach the application over HTTPS. Enforce perimeter controls (firewall rules, VPN requirements) to prevent unauthenticated internet-facing exposure of PeopleSoft instances until the patch can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

