Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 9.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated local attackers who have logon to the infrastructure where Oracle Product Lifecycle Analytics runs can exploit a flaw in the installation component that allows unauthorized creation, deletion, or modification of critical data. The vulnerability results in loss of confidentiality and integrity and grants the attacker full control over accessible data, possibly affecting other products within the supply chain.

Affected Systems

Oracle Corporation’s Oracle Product Lifecycle Analytics version 3.6.1 is affected. No other product versions were identified in the advisory.

Risk and Exploitability

The flaw carries a CVSS 3.1 score of 9.0, indicating a high severity impact on confidentiality and integrity. The EPSS score is below 1%, suggesting a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers require local system access or logon rights on the infrastructure where the product is deployed; the vulnerability is classified as easily exploitable once those conditions are met, and the scope change can extend its impact to other products.

Generated by OpenCVE AI on August 4, 2026 at 16:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the July 2026 CPU update for Product Lifecycle Analytics to address the installation issue.
  • If the patch cannot be applied immediately, restrict local logon access to the infrastructure hosting the product by enforcing strict authentication and least privilege principles and block untrusted accounts from running the application.
  • Continuously monitor system logs for abnormal creation, deletion, or modification events and perform regular security audits to ensure no unauthorized changes have been made to critical data.

Generated by OpenCVE AI on August 4, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Local Data Modification in Oracle Product Lifecycle Analytics
Weaknesses CWE-640
CWE-732

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Enables Data Modification in Oracle Product Lifecycle Analytics
Weaknesses CWE-269
CWE-284

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Enables Data Modification in Oracle Product Lifecycle Analytics
Weaknesses CWE-269
CWE-284

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Enables Unauthorized Data Modification in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284
CWE-732

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Enables Unauthorized Data Modification in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284
CWE-732

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 9.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:34:02.987Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61174

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password

  • CWE-732

    Incorrect Permission Assignment for Critical Resource