Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution (inferred)
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker without authentication to exploit the HTTP interface of Oracle Product Lifecycle Analytics 3.6.1. The flaw is an authentication bypass that can be triggered from any network location that can reach the service, permitting a full takeover of the application. Successful exploitation would result in a complete loss of confidentiality, integrity, and availability of the service, effectively granting the attacker remote code execution capabilities (inferred). The weakness maps to CWE‑287 (Authentication Bypass) and CWE‑306 (Missing Authentication for Continuous Access).

Affected Systems

The affected product is Oracle Corporation’s Product Lifecycle Analytics version 3.6.1, a component of Oracle Supply Chain. This is the only supported version listed as vulnerable. The product runs on an HTTP interface that is accessible to unauthenticated users, and the vulnerability is tied to the Core component of the application.

Risk and Exploitability

The CVSS v3.1 score of 9.8 indicates critical severity for confidentiality, integrity, and availability. The EPSS score is less than 1 %, implying a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is simple – it requires only network access to the risk significant for exposed instances. Administrators should treat this as a high‑priority issue and prioritize remediation.

Generated by OpenCVE AI on September 18, 2026 at 15:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for Product Lifecycle Analytics 3.6.1 that removes the authentication bypass.
  • If the patch is unavailable, restrict inbound traffic to the HTTP interface so that only trusted IP ranges or host‑based firewalls can reach the service.
  • Enable comprehensive audit logging on the application and configure alerts for any unauthenticated access attempts to the HTTP endpoint.
  • Follow Oracle’s security bulletin to verify that the service is running over HTTPS with proper certificate validation, and disable any insecure HTTP endpoints if they remain accessible.

Generated by OpenCVE AI on September 18, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass in Oracle Product Lifecycle Analytics

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:35.774Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83261

cve-icon Vulnrichment

Updated: 2026-09-15T22:45:02.545Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:38.403

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:30:11Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function