Executive brief
A security vulnerability has been identified in Oracle PeopleSoft Enterprise SCM Manufacturing, a software suite used by organizations to manage large-scale manufacturing and supply chain operations. An unauthorized person could exploit this flaw over the network to gain access to sensitive business data. This could lead to the exposure of proprietary manufacturing processes, inventory details, or other critical corporate information.
Technical details
A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Manufacturing version 9.2. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by the SCM Manufacturing module. The vulnerability primarily impacts confidentiality, as indicated by the CVSS vector (C:H). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle PeopleSoft Enterprise SCM Manufacturing 9.2
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update
- 2026-07-21: advisory: NVD publication date