Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Takeover
Action: Immediate Patch
AI Analysis

Impact

A flaw in the installation component of Oracle Product Lifecycle Analytics allows a low‑privileged attacker who can reach the system over HTTP to gain full control of the application.

Affected Systems

Oracle Product Lifecycle Analytics version 3.6.1, part of Oracle Supply Chain’s Product Lifecycle Analytics suite.

Risk and Exploitability

The CVSS base score of 7.5 indicates moderate to high severity, while the EPSS score of less than 1% shows a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, but because it can be triggered remotely over an open HTTP port with no user interaction, attackers can potentially compromise the system if they can reach the vulnerable endpoint.

Generated by OpenCVE AI on September 20, 2026 at 08:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch to remove the installation issue in version 3.6.1.
  • Restrict HTTP traffic to the installation endpoints using firewalls or network segmentation so only trusted hosts can access them.
  • Enforce strict access controls on installation‑related functions to ensure that only authorized users can execute configuration changes.

Generated by OpenCVE AI on September 20, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Allows Complete Takeover of Oracle Product Lifecycle Analytics v3.6.1

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Installation Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Installation Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:39.448Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83262

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:58.384Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:38.517

Modified: 2026-09-17T14:17:38.430

Link: CVE-2026-83262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management