Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise SCM Order Management, a software suite used by organizations to manage supply chains and customer orders. An attacker who already has basic access to the server where this software is running could exploit this flaw to take full control of the application. This could lead to the unauthorized viewing of sensitive business data, modification of order records, or a complete disruption of supply chain operations.
Technical details
This vulnerability is located in the Security component of Oracle PeopleSoft Enterprise SCM Order Management version 9.2. It is classified as a local privilege escalation or application compromise flaw, requiring the attacker to have existing logon access to the underlying infrastructure where the software executes. The exploit is described as easily exploitable (low attack complexity) and does not require user interaction. A successful attack allows a low-privileged user to achieve a complete takeover of the PeopleSoft Enterprise SCM Order Management environment. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise SCM Order Management 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory