ZeroHour

CVE-2026-83263

niche

Low-Privilege Takeover Flaw in Oracle Product Lifecycle Analytics 3.6.1

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83263 is a difficult-to-exploit vulnerability in the Installation Issues component of Oracle Product Lifecycle Analytics, part of Oracle Supply Chain, affecting supported version 3.6.1. A remote attacker with network access via HTTP who already holds a low-privileged account on the product can exploit the flaw to fully compromise the Oracle Product Lifecycle Analytics installation. Successful attacks impact confidentiality, integrity, and availability, effectively resulting in a takeover of the application, with a CVSS 3.1 base score of 7.5 (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Only organizations running the affected 3.6.1 release are exposed, and the high attack complexity means reliable exploitation is nontrivial. There is no evidence of in-the-wild exploitation, the CVE is not on the CISA KEV list, and no public proof of concept is known.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw as soon as it is released and confirm you are not running the affected 3.6.1 release. Restrict HTTP/HTTPS access to the Product Lifecycle Analytics console to trusted networks or VPN, and review and minimize low-privileged application accounts, since exploitation requires an authenticated foothold. Audit logs for suspicious activity by low-privilege users against the installation component as a precaution.

Affected
Oracle Product Lifecycle Analytics (Oracle Supply Chain)3.6.1
Estimated exposure
nicheNo basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.