CVE-2026-83264
nicheLocal Privilege Escalation via Installation Flaw in Oracle Product Lifecycle Analytics 3.6.1
Oracle Product Lifecycle Analytics 3.6.1, part of the Oracle Supply Chain suite, contains a vulnerability in its installation component that lets a low-privileged attacker who already has logon access to the server hosting the product compromise the entire application. Exploitation requires only local access with an ordinary low-privilege OS or application account, needs no user interaction, and is rated easily exploitable. Because the flaw changes scope, a successful attack can also significantly impact additional products beyond Product Lifecycle Analytics, yielding unauthorized creation, deletion, or modification of critical data as well as full read access to all data the product can reach. The issue is scored CVSS 3.1 8.4 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N), with high confidentiality and integrity impact but no availability impact. No public proof-of-concept exists and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE and upgrade Product Lifecycle Analytics from 3.6.1 to the patched release. Restrict local OS logon and interactive access on servers hosting the product to trusted administrators only, since exploitation requires a low-privilege local account. Audit the installation for weak file, directory, or service permissions left by the installer, and review logs for unauthorized data creation, modification, or deletion within the product and adjacent in-scope systems.
| Oracle Product Lifecycle Analytics (Oracle Supply Chain) | 3.6.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.