Description
Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the security component of Oracle PeopleSoft Enterprise SCM Order Management, identified as CWE-284 (Access Control), allows an attacker who is not authenticated to manipulate or read critical data over HTTP. The flaw can lead to the creation, deletion, or modification of orders and related information, directly compromising confidentiality and integrity. Such changes could disrupt business processes, lead to financial loss, or create legal exposure for the organization.

Affected Systems

Oracle PeopleSoft Enterprise SCM Order Management version 9.2 is affected. No other versions were explicitly listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 marks this as a critical vulnerability. The attack vector is over the network via HTTP, requires no authentication, and presents minimal effort for automated exploitation, albeit a very low EPSS of less than 1%. The flaw is not yet in the CISA KEV catalog, but its high severity and network accessibility make it a high priority for remediation. An attacker can directly alter or read order data, potentially opening doors for further privilege enhancement or data exfiltration.

Generated by OpenCVE AI on August 4, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security advisories for the latest update for PeopleSoft Enterprise SCM Order Management 9.2 and apply the available patch or update.
  • Restrict or block HTTP access to the Order Management service from untrusted network segments until a patch is applied.
  • Continuously monitor audit logs for unauthorized creation, deletion, or modification events and verify that these actions no longer occur after patch deployment.

Generated by OpenCVE AI on August 4, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Tampering via Unauthenticated HTTP Access in Oracle PeopleSoft Enterprise SCM Order Management 9.2

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Tampering via Unauthenticated HTTP Access in Oracle PeopleSoft Enterprise SCM Order Management 9.2

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle PeopleSoft Enterprise SCM Order Management 9.2

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle PeopleSoft Enterprise SCM Order Management 9.2
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Order Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_order_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Order Management
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:25:48.753Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61059

cve-icon Vulnrichment

Updated: 2026-07-24T14:25:42.669Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses