Description
Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Supplier Contract Management executes to compromise PeopleSoft Enterprise SCM Supplier Contract Management. While the vulnerability is in PeopleSoft Enterprise SCM Supplier Contract Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Supplier Contract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Security component of Oracle PeopleSoft Enterprise SCM Supplier Contract Management 9.2 and is a local privilege escalation flaw (CWE‑269). A user with low‑privileged logon on the host can exploit the weakness to elevate privileges and compromise the application, leading to a full takeover with loss of confidentiality, integrity, and availability.

Affected Systems

Oracle PeopleSoft Enterprise SCM Supplier Contract Management version 9.2 is affected. The flaw exists in the Security module and may be exercised by anyone who has local access credentials to the infrastructure hosting the application, potentially impacting other integrated components within the same deployment.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates high severity impacts across confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests a low likelihood of current wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the local attack vector and low‑privilege requirement mean an attacker who gains local credentials could elevate privileges, trigger a scope change, and ultimately seize the application, with cascading effects on any co‑deployed systems.

Generated by OpenCVE AI on August 2, 2026 at 20:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security update for PeopleSoft Enterprise SCM Supplier Contract Management 9.2 that addresses the privilege‑escalation weakness (CWE‑269) as outlined in the July 2026 advisory.
  • Restrict local user accounts to the minimum privileges required to host the application, limiting the potential impact of the insufficient‑authorization flaw.
  • Enable detailed logging and monitoring of privileged actions on both the application and underlying servers, and audit logs regularly to detect anomalous privilege use.

Generated by OpenCVE AI on August 2, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle PeopleSoft SCM Supplier Contract Management 9.2

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Exploit Enables Takeover of PeopleSoft Enterprise SCM Supplier Contract Management
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Exploit Enables Takeover of PeopleSoft Enterprise SCM Supplier Contract Management
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Supplier Contract Management executes to compromise PeopleSoft Enterprise SCM Supplier Contract Management. While the vulnerability is in PeopleSoft Enterprise SCM Supplier Contract Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Supplier Contract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Supplier Contract Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_supplier_contract_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Supplier Contract Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Supplier Contract Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:21:41.816Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61063

cve-icon Vulnrichment

Updated: 2026-07-24T14:21:36.253Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management