Security Vulnerability in PeopleSoft Enterprise SCM Mobile Inventory Management by Oracle
CVE-2026-61077

7.5HIGH

What is CVE-2026-61077?

A security vulnerability has been identified in Oracle's PeopleSoft Enterprise SCM Mobile Inventory Management product, specifically affecting version 9.2. This vulnerability can be exploited by a low privileged attacker who has logged into the infrastructure where the product operates. The compromise allows the attacker to gain unauthorized creation, deletion, or modification access to critical data within the PeopleSoft environment. While the vulnerability is specific to the SCM Mobile Inventory Management product, its impact may extend to additional connected products. Successful exploitation can lead to severe consequences, enabling unauthorized access to potentially all data managed by the application.

Affected Version(s)

PeopleSoft Enterprise SCM Mobile Inventory Management 9.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.