Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Order Management executes to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Order Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle PeopleSoft Enterprise SCM Order Management 9.2

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle PeopleSoft Enterprise SCM Order Management 9.2
Weaknesses CWE-285

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle PeopleSoft Enterprise SCM Order Management 9.2
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Order Management executes to compromise PeopleSoft Enterprise SCM Order Management. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Order Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Scm Order Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_scm_order_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Scm Order Management
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2026-07-21T21:37:53.881Z

Updated: 2026-07-24T14:31:33.753Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61055

cve-icon Vulnrichment

Updated: 2026-07-24T14:31:25.745Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:36.290

Modified: 2026-08-04T18:10:12.990

Link: CVE-2026-61055

cve-icon Redhat

No data.