Executive brief
A security vulnerability exists in Oracle PeopleSoft Enterprise SCM Supplier Contract Management, a software suite used by organizations to manage vendor relationships and procurement contracts. A low-privileged user with access to the underlying system can exploit this flaw to take full control of the application. This could lead to the unauthorized disclosure of sensitive contract data, disruption of procurement operations, and potential impacts on other connected business systems.
Technical details
A vulnerability in the Security component of Oracle PeopleSoft Enterprise SCM Supplier Contract Management (version 9.2) allows for a complete system compromise. The flaw is categorized as easily exploitable by a low-privileged attacker who has local logon access to the infrastructure where the software executes. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact security domains beyond the PeopleSoft application itself. The attack does not require user interaction and results in high impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle PeopleSoft Enterprise SCM Supplier Contract Management 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published