Executive brief
Oracle PeopleSoft Enterprise SCM Manufacturing, a software suite used to manage supply chains and manufacturing processes, contains a security vulnerability in its Security component. An unauthenticated attacker could exploit this flaw over the network to gain full access to sensitive manufacturing data. This could lead to the unauthorized viewing, modification, or deletion of critical business information, potentially disrupting operations and compromising proprietary data.
Technical details
A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Manufacturing version 9.2. The flaw allows an unauthenticated attacker with network access via HTTPS to compromise the system, though the attack complexity is rated as high, suggesting specific conditions or timing may be required for success. If exploited, the attacker can achieve complete unauthorized access to data (Confidentiality) and unauthorized modification or deletion of data (Integrity). The vulnerability does not impact system availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise SCM Manufacturing 9.2
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-61210 was published to the NVD.