Security Vulnerability in Oracle PeopleSoft SCM Supplier Contract Management
CVE-2026-61063

8.8HIGH

What is CVE-2026-61063?

A security vulnerability exists in Oracle's PeopleSoft Enterprise SCM Supplier Contract Management product, specifically in version 9.2. This vulnerability allows low privileged attackers with access to the infrastructure to exploit weaknesses within the system, potentially leading to a takeover of the Supplier Contract Management application. Although the primary impact is on this specific component, the nature of the vulnerability could also affect other associated products. Organizations utilizing this version should address this issue promptly to safeguard against unauthorized access and maintain system integrity.

Affected Version(s)

PeopleSoft Enterprise SCM Supplier Contract Management 9.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.