External risk intelligence

Oracle PeopleSoft eProcurement Unauthorized Data Access and Modification Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-61207

The vulnerability affects a PeopleSoft eProcurement component accessible via HTTP without authentication. Enterprise procurement portals are frequently deployed as internet-facing web applications or services to facilitate access for external vendors and remote employees, making them a common part of the exposed web-facing attack surface.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle's PeopleSoft Enterprise SCM eProcurement product, specifically affecting the Manage Requisition Status component. This issue is easily exploitable by unauthenticated attackers over the network and could lead to unauthorized access, modification, or deletion of sensitive data. The impact may extend beyond the direct component to other connected PeopleSoft products.

  • Access to critical procurement data is at risk.
  • Unauthenticated network access can compromise sensitive information.
  • Confirm relevance and verify exposure to understand potential impact.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability over the network to gain unauthorized access to sensitive data or modify existing data within PeopleSoft Enterprise SCM eProcurement. This could potentially lead to a broad impact across other connected PeopleSoft products due to the scope change of this vulnerability.

  • No authentication required.
  • Network access triggers vulnerability.
  • Unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise PeopleSoft Enterprise SCM eProcurement, potentially leading to unauthorized access or modification of critical data. While the vulnerability is in eProcurement, attacks might impact other PeopleSoft products.

  • Sensitive procurement data could be exposed.
  • Attacker gains unauthorized network access.
  • Unauthorized access to critical data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Oracle PeopleSoft Enterprise SCM eProcurement. Application owners and infrastructure teams are likely responsible for managing this system. The first practical step is to identify all instances of PeopleSoft Enterprise SCM eProcurement, confirm their reachability and business criticality, identify the accountable owner, and then plan remediation based on the assessed risk.

  • Application owners and infrastructure teams.
  • Verify exposure and business criticality.
  • Coordinate with vendor and plan remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle PeopleSoft Enterprise SCM eProcurement?

PeopleSoft Enterprise SCM eProcurement is a module within Oracle's supply chain management suite designed to automate and manage the requisition-to-purchase order process. Organizations use it to streamline purchasing activities, track requisition statuses, and manage supplier interactions. It serves as a centralized web portal where employees and authorized vendors interact with procurement data.

What does CVE-2026-61207 mean for system security?

This vulnerability represents a significant security weakness that allows an unauthorized party to interact with the eProcurement system without needing a login. Because the flaw allows for potential scope change, an attacker might not only access or change requisition data but also compromise connected PeopleSoft products, potentially gaining broader unauthorized access to information across the integrated enterprise suite.

How is this vulnerability triggered by an attacker?

An attacker triggers this vulnerability by sending specially crafted HTTP requests over a network to the Manage Requisition Status component. Crucially, the system does not require any credentials or user interaction to process these malicious requests. The bug is not triggered by legitimate user actions or internal system processes, but rather requires direct, unauthenticated network connectivity to the affected eProcurement service.

Do I need to worry if my eProcurement portal is internal?

According to Halo Surface Signal, this vulnerability is particularly concerning for deployments accessible via the internet, as these are common targets. While internal-only portals face a reduced attack surface, the risk remains if the application is reachable from anywhere within your internal network. You should evaluate whether the portal's current network placement aligns with your organization's risk tolerance for unauthenticated access.

What should I do first to address this CVE?

Begin by creating a definitive inventory of all PeopleSoft Enterprise SCM eProcurement instances running in your environment. Once identified, determine the network reachability of each instance and establish who is responsible for the system's administration. Prioritize reviewing the official Oracle security documentation referenced in this advisory to understand the available security updates and coordinate with your technical teams to plan for their application.

References