ZeroHour

CVE-2026-83261

niche

Unauthenticated Takeover Vulnerability in Oracle Product Lifecycle Analytics 3.6.1

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

A critical (CVSS 9.8) vulnerability in the Core component of Oracle Product Lifecycle Analytics, part of the Oracle Supply Chain suite, affects version 3.6.1. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction, and successful attacks can result in complete takeover of the Product Lifecycle Analytics installation with high impact on confidentiality, integrity, and availability. In practice, this means an attacker who can reach the application's web endpoint could seize control of the product and its data. Organizations running the affected version exposed to internal or external networks are at risk. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw in Product Lifecycle Analytics and confirm the patched version in the relevant Oracle advisory, since only 3.6.1 is listed as affected. Until patched, restrict HTTP access to the application to trusted networks (VPN, firewall allowlisting) rather than leaving it broadly reachable, and front it with authentication at a proxy or SSO layer if possible. Review application and server logs for unexplained account changes, unknown sessions, or data exfiltration indicating prior compromise.

Affected
Oracle Product Lifecycle Analytics (Oracle Supply Chain)
Estimated exposure
nicheunknown; plausibly low-thousands of enterprise deployments at most (order-of-magnitude estimate) — Oracle Product Lifecycle Analytics is a specialized enterprise analytics application typically deployed by a limited number of large supply-chain organizations on-premises or in private clouds, and no public active-install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.