Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Oracle Product Lifecycle Analytics version 3.6.1 has an installation issue that lets an attacker with low‑privilege access on the host create, modify, or delete critical data, and potentially gain full access to any data stored in the product. The flaw offers a direct route for privilege escalation, compromising confidentiality and integrity but not availability.

Affected Systems

The vulnerability affects Oracle Product Lifecycle Analytics 3.6.1, a component of Oracle Supply Chain. Because the flaw can alter the scope, other Oracle products running on the same infrastructure may also be exposed.

Risk and Exploitability

The CVSS score of 8.4 denotes high severity, while the EPSS score of less than 1 % suggests that exploitation is unlikely but not impossible. The vulnerability is exploitable from requires no network connectivity or special tooling. The flaw is not listed in the CISA KEV catalog, indicating no known widespread attacks so far. Nonetheless, the potential for unauthorized data creation, deletion, or modification makes it a critical risk for organizations that rely on Oracle Product Lifecycle Analytics.

Generated by OpenCVE AI on September 20, 2026 at 08:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Product Lifecycle Analytics update that resolves the installation issue.
  • Restrict local user accounts to the minimal privileges required for Oracle Product Lifecycle Analytics operation.
  • Conduct a security audit to verify that no unintended data access paths remain and that other Oracle products are not exposed.

Generated by OpenCVE AI on September 20, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Installation Issue Enables Low-Privilege Compromise of Oracle Product Lifecycle Analytics

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Unauthorized.6.1
Weaknesses CWE-269

Wed, 16 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Unauthorized.6.1
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Product Lifecycle Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:49.936Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83264

cve-icon Vulnrichment

Updated: 2026-09-18T18:16:27.105Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:38.737

Modified: 2026-09-18T19:16:52.007

Link: CVE-2026-83264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses