Description
Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Manufacturing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Security component of Oracle PeopleSoft Enterprise SCM Manufacturing 9.2 allows an attacker with network reachability over HTTP to authenticate without credentials and obtain unrestricted read access to sensitive data. The vulnerability leads to a high confidentiality impact without affecting integrity or availability, as described in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.

Affected Systems

Oracle PeopleSoft Enterprise SCM Manufacturing 9.2 is the only product and version explicitly listed as affected. No other versions or products were mentioned in the advisory.

Risk and Exploitability

The CVSS base score of 7.5 indicates a medium to high severity for an unauthenticated attacker. The EPSS score of less than 1% suggests the probability of exploitation in the wild is low, and the vulnerability is currently not listed in the CISA KEV catalog. Inferred from the description, the likely attack vector is over the network via HTTP, requiring no authentication or special user privileges. The impact would be unauthorized access to all data exposed through PeopleSoft, posing a significant confidentiality risk.

Generated by OpenCVE AI on August 4, 2026 at 01:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the PeopleSoft 9.2 security patch detailed in Oracle’s CPU July 2026 advisory
  • Limit HTTP access to the PeopleSoft instance by enforcing firewall rules or VPNs that allow only trusted IP addresses
  • Configure PeopleSoft to enforce authentication on all pages and monitor logs for suspicious access patterns

Generated by OpenCVE AI on August 4, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exposure in Oracle PeopleSoft SCM Manufacturing 9.2

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exposure in Oracle PeopleSoft SCM Manufacturing 9.2

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Privilege Escalation in PeopleSoft Enterprise SCM Manufacturing

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Privilege Escalation in PeopleSoft Enterprise SCM Manufacturing
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Manufacturing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Manufacturing
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_manufacturing:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Manufacturing
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Peoplesoft Enterprise Scm Manufacturing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:18:18.936Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61088

cve-icon Vulnrichment

Updated: 2026-07-23T19:18:14.671Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses