Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Product Lifecycle Analytics version 3.6.1 that allows an attacker with low privilege and network access over Oracle Net to gain unauthorized access to critical data and to insert, update or delete data. The impact includes confidentiality and integrity compromises, as reflected in the CVSS vector. The issue is flagged as an installation issue but the attack could extend to additional products, evidencing a scope change.

Affected Systems

The affected product is Oracle Product Lifecycle Analytics by Oracle Corporation, version 3.6.1. No other affected versions or products are listed in the available data.

Risk and Exploitability

The CVSS base score of 8.5 marks this as high severity. The EPSS score is less than 1%, indicating a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based via Oracle Net, and requires only low privilege to execute. Successful exploitation can allow an attacker to gain full access to all accessible data and alter or delete that data, potentially impacting additional products if the scope is expanded.

Generated by OpenCVE AI on August 21, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of Oracle Product Lifecycle Analytics that contains the fix.
  • Restrict network access to Oracle Net for low‑privileged accounts, limiting exposure.
  • Monitor audit logs for unauthorized changes and consider revoking or tightening privileges on affected accounts.

Generated by OpenCVE AI on August 21, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Oracle Product Lifecycle Analytics

Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Exploit of Oracle Product Lifecycle Analytics via Oracle Net
Weaknesses CWE-269

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Exploit of Oracle Product Lifecycle Analytics via Oracle Net
Weaknesses CWE-269
CWE-284

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Access Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-269
CWE-284

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Access Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:55:52.214Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71049

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:23.236Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:04.713

Modified: 2026-08-27T18:52:15.133

Link: CVE-2026-71049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses