Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
Published: 2026-07-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the Oracle Product Lifecycle Analytics component enables an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data or complete access to all accessible data, while also allowing a partial denial of service. The flaw results in a significant confidentiality breach and a reduction in availability.

Affected Systems

Oracle Corporation's Product Lifecycle Analytics version 3.6.1 is affected. The vulnerability may also impact other related products in the Oracle Supply Chain ecosystem.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3 and is rated low for exploitation probability with an EPSS score of <1%; it is not currently listed in the CISA KEV catalog. The likely attack vector is a remote network-based HTTP request that bypasses authentication controls to achieve unauthorized data access and disrupt service.

Generated by OpenCVE AI on August 4, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle's security advisories and install the latest patch for Product Lifecycle Analytics 3.6.1 as soon as it is available
  • In the interim, restrict inbound HTTP traffic to the Product Lifecycle Analytics server to only trusted IP addresses
  • Enable strict authentication mechanisms and monitor for suspicious HTTP requests to detect potential exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle Product Lifecycle Analytics

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle Product Lifecycle Analytics

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Unauthorized Access and Partial Denial of Service in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Unauthorized Access and Partial Denial of Service in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:32:39.871Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61175

cve-icon Vulnrichment

Updated: 2026-07-23T15:32:31.947Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-306

    Missing Authentication for Critical Function