Summary
CVE-2026-61205 is a high-severity improper access control vulnerability (CWE-284) affecting Oracle PeopleSoft Enterprise SCM Purchasing version 9.2. The flaw allows unauthenticated remote attackers to perform unauthorized creation, deletion, or modification of critical purchasing data over HTTP, and to read a subset of accessible data, without requiring any credentials or user interaction. It was published on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update and carries a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: Improper access control (CWE-284) in the Purchasing component of Oracle PeopleSoft Enterprise SCM Purchasing, allowing requests to reach privileged data operations without authentication checks.
- Trigger conditions: An attacker sends crafted HTTP requests to the exposed PeopleSoft web application — no credentials, no prior session, and no victim interaction are required.
- Attack vector: Network (HTTP); Attack Complexity: Low; Privileges Required: None; User Interaction: None; Scope: Unchanged.
- Impact: Successful exploitation enables unauthorized creation, deletion, or modification of critical data across the PeopleSoft SCM Purchasing module (High integrity impact), as well as unauthorized read access to a subset of accessible data (Low confidentiality impact). No availability impact is associated with this vulnerability.
Affected software
- Oracle PeopleSoft Enterprise SCM Purchasing version 9.2
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Mitigation and recommended actions
- Immediate action: Apply Oracle’s July 2026 Critical Patch Update patches for Oracle PeopleSoft Enterprise products. Oracle has directed customers to the associated Patch Availability Document (CPU277 in PeopleSoft support documentation) for specific installation instructions.
- If patching is not immediately feasible: Restrict network access to PeopleSoft web application endpoints at the perimeter, ensuring SCM Purchasing interfaces are not directly reachable from untrusted networks or the public internet.
- Oracle strongly recommends applying Critical Patch Update security patches as soon as possible.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

