Summary
CVE-2026-61207 is a critical improper access control vulnerability (CWE-284) in the Manage Requisition Status component of Oracle PeopleSoft Enterprise SCM eProcurement. With a CVSS 3.1 base score of 9.3 (Critical), it allows unauthenticated remote attackers to access critical procurement data and perform unauthorized modifications across connected system components, with no user interaction required. The vulnerability was disclosed as part of Oracle’s July 2026 Critical Patch Update (July 21, 2026).
Technical details
- Root cause: Improper access control (CWE-284) in the Manage Requisition Status component of PeopleSoft Enterprise SCM eProcurement, allowing requests to be processed without authentication enforcement.
- Trigger conditions: Exploitable over the network via HTTP with no prerequisites — no authentication, no privileges, and no user interaction required.
- Attack vector: Network-accessible; attackers with HTTP access to an internet-facing PeopleSoft instance can directly exploit the vulnerable component.
- Impact: Successful exploitation enables unauthorized access to critical data (high confidentiality impact) and unauthorized modification of some accessible data (low integrity impact). The Scope:Changed metric indicates that exploitation can affect components and data beyond the directly vulnerable eProcurement module itself, extending potential impact to connected enterprise systems.
Affected software
- Oracle PeopleSoft Enterprise SCM eProcurement 9.2
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU July 2026) for PeopleSoft Enterprise SCM eProcurement. Oracle has released patches addressing this vulnerability; patch details and installation instructions are available through the official Oracle CPU advisory and Oracle Support (My Oracle Support Doc ID CPU277).
- Network mitigation (if patching is delayed): Restrict network-level access to PeopleSoft eProcurement web interfaces by enforcing perimeter controls (e.g., firewall rules, VPN requirements, or IP allowlisting) to limit exposure to trusted networks only, reducing the attack surface while patching is arranged.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

