Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Patch
AI Analysis

Impact

The vulnerability in Oracle Product Lifecycle Analytics 3.6.1 is an installation issue that permits a low‑privileged attacker who can reach the service over HTTP to compromise the application. Successful exploitation enables full takeover, giving the attacker control over data and application functions. The flaw is a privilege escalation and authorization check weakness identified as CWE‑269.

Affected Systems

Oracle Corporation’s Product Lifecycle Analytics version 3.6.1; all installations of this specific version are affected. The vulnerability is tied to the installation component of the product.

Risk and Exploitability

The CVSS base score of 7.5 highlights high confidentiality, integrity and availability impact. The EPSS score of less than 1% indicates a presently low likelihood of exploitation, but because the flaw permits takeover, it remains a serious risk. The vector is network‑based via the HTTP interface and requires only low privilege, with no user interaction. Attack complexity is high due to difficulty to exploit, but a successful attack would provide attackers with full control.

Generated by OpenCVE AI on September 20, 2026 at 08:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Oracle’s website for updated releases that include the fix and deploy the latest supported version of Product Lifecycle Analytics 3.6.1.
  • Restrict network access to the installation component’s HTTP interface to only trusted administrative hosts using firewall rules or VLAN segmentation.
  • Enforce least privilege on the service accounts that run Product Lifecycle Analytics, removing any unnecessary local or domain permissions that could be leveraged for privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in Product Lifecycle Analytics

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Installation Issue Enabling Remote Takeover in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Installation Issue Enabling Remote Takeover in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:39.303Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83263

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:55.427Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:38.623

Modified: 2026-09-17T14:17:38.550

Link: CVE-2026-83263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management