Description
Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Security component of Oracle PeopleSoft Enterprise SCM Order Management 9.2 allows an unauthenticated attacker with network access via HTTPS to breach the application, enabling unauthorized read of critical data or full access to all data exposed by the system. The vulnerability results in a loss of confidentiality with no impact on integrity or availability.

Affected Systems

Oracle Corporation’s PeopleSoft Enterprise SCM Order Management, version 9.2. Only that release is affected by this issue.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 marks this vulnerability as high severity, while the EPSS score of less than 1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is HTTPS network access; the attacker does not need authenticated credentials to trigger the flaw and can submit crafted requests over SSL to obtain confidential data.

Generated by OpenCVE AI on August 4, 2026 at 01:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest PeopleSoft Enterprise SCM Order Management 9.2 patch released by Oracle in the July 2026 security advisory
  • Restrict HTTPS traffic to the application to approved IP ranges and enforce IP-based access controls
  • Enable detailed logging of all authentication and data-access events and continuously review logs for abnormal activity

Generated by OpenCVE AI on August 4, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTPS Access Enables Data Breach in Oracle PeopleSoft Enterprise SCM Order Management 9.2

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTPS Access Enables Data Breach in Oracle PeopleSoft Enterprise SCM Order Management 9.2

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Enables Data Breach in Oracle PeopleSoft Enterprise SCM Order Management

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Enables Data Breach in Oracle PeopleSoft Enterprise SCM Order Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Order Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_order_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Order Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:41:00.354Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61086

cve-icon Vulnrichment

Updated: 2026-07-23T19:40:56.099Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses