Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a high privileged attacker who can reach the system over Oracle Net to create, delete, or modify critical data within Oracle Product Lifecycle Analytics. The impact includes unauthorized access to all data accessible by the product and the potential for complete loss of confidentiality and integrity as listed in the CVSS vector. The weakness is consistent with a flaw in access control mechanisms.

Affected Systems

Oracle Corporation’s Oracle Product Lifecycle Analytics, specifically version 3.6.1.

Risk and Exploitability

The CVSS 3.1 base score of 8.7 indicates a high severity with confidentiality and integrity impacts. The EPSS score of < 1% suggests a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers with network access and high privileges can exploit the flaw by connecting to Oracle Net, achieving elevated privileges and modifying or deleting data, thereby changing the scope of the vulnerability.

Generated by OpenCVE AI on August 20, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle patch or update that addresses this issue for Product Lifecycle Analytics 3.6.1.
  • Restrict network connectivity to Oracle Net, limiting access to trusted hosts only.
  • Enforce strict access control and least privilege on the affected environment to prevent unauthorized data modification.

Generated by OpenCVE AI on August 20, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title High Privilege Data Modification Vulnerability in Oracle Product Lifecycle Analytics 3.6.1

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Modification in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Modification in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:55:57.772Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71050

cve-icon Vulnrichment

Updated: 2026-08-20T17:51:18.749Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:04.830

Modified: 2026-08-27T18:52:05.737

Link: CVE-2026-71050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:30:05Z

Weaknesses