CVE-2026-83261
nicheUnauthenticated Takeover Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
A critical (CVSS 9.8) vulnerability in the Core component of Oracle Product Lifecycle Analytics, part of the Oracle Supply Chain suite, affects version 3.6.1. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction, and successful attacks can result in complete takeover of the Product Lifecycle Analytics installation with high impact on confidentiality, integrity, and availability. In practice, this means an attacker who can reach the application's web endpoint could seize control of the product and its data. Organizations running the affected version exposed to internal or external networks are at risk. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw in Product Lifecycle Analytics and confirm the patched version in the relevant Oracle advisory, since only 3.6.1 is listed as affected. Until patched, restrict HTTP access to the application to trusted networks (VPN, firewall allowlisting) rather than leaving it broadly reachable, and front it with authentication at a proxy or SSO layer if possible. Review application and server logs for unexplained account changes, unknown sessions, or data exfiltration indicating prior compromise.
| Oracle Product Lifecycle Analytics (Oracle Supply Chain) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.