ZeroHour

CVE-2026-83262

niche

Difficult-to-Exploit Takeover Flaw in Oracle Product Lifecycle Analytics 3.6.1

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

Oracle Product Lifecycle Analytics 3.6.1, part of the Oracle Supply Chain suite, contains a flaw in its Installation Issues component that allows a low-privileged, authenticated attacker with network access via HTTP to compromise the product. Exploitation is rated as difficult (Attack Complexity: High), meaning repeated attempts and favorable conditions are typically required. A successful attack can result in a full takeover of Oracle Product Lifecycle Analytics, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Only version 3.6.1 is listed as affected. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and there is no evidence of exploitation in the wild.

What to do: Apply Oracle's Critical Patch Update remediation for CVE-2026-83262 as soon as it is released for your release line, since no fixed version is specified in the advisory. In the meantime, restrict network and HTTP access to Product Lifecycle Analytics endpoints (VPN/IP allowlisting) and audit low-privileged accounts for anomalous activity. Verify which installations in your environment run the affected 3.6.1 version and prioritize patching internet-reachable deployments.

Affected
Oracle Product Lifecycle Analytics (Oracle Supply Chain)
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments (no public counts) — Oracle Product Lifecycle Analytics is a licensed, specialized enterprise supply-chain analytics product deployed only within Oracle customer environments, and no public active-install counts or internet-exposure scan data are available, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.