Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privilege escalation flaw exists in the installation component of Oracle Product Lifecycle Analytics that allows an attacker with host access to fully compromise the application. The vulnerability has the potential to compromise confidentiality, integrity, and availability of the product and, because the vulnerability also impacts other associated Oracle Supply Chain products, it can lead to broader system compromise.

Affected Systems

Oracle Corporation’s Oracle Product Lifecycle Analytics, specifically version 3.6.1, is the affected release. No other product versions are listed as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 classifies this as a high‑severity issue. The EPSS score is below 1%, indicating a low but non‑zero probability of exploitation, while the lack of a KEV listing does not diminish the potential damage. The local attack vector combined with low privilege requirements makes the exploit highly feasible in environments where host access is not strictly controlled, and the scope change allows the compromise to spill over to related products.

Generated by OpenCVE AI on August 21, 2026 at 02:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade Oracle Product Lifecycle Analytics to a non‑affected version.
  • Restrict local logon rights on the host to trusted administrators and enforce least‑privilege policies.
  • Review and tighten file and directory permissions for installation directories to prevent unauthorized changes.
  • Consider network segmentation to isolate the server hosting the application from critical network segments.

Generated by OpenCVE AI on August 21, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Product Lifecycle Analytics Installation Component

Thu, 20 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Product Lifecycle Analytics Installation Component

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Product Lifecycle Analytics Leading to Full Application Compromise
Weaknesses CWE-264

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Product Lifecycle Analytics Leading to Full Application Compromise
Weaknesses CWE-264

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Full Compromise of Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284
CWE-862

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Full Compromise of Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:55:54.431Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71051

cve-icon Vulnrichment

Updated: 2026-08-20T17:51:20.791Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:04.940

Modified: 2026-08-27T18:51:56.693

Link: CVE-2026-71051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:00:04Z

Weaknesses