ZeroHour

CVE-2026-83264

niche

Local Privilege Escalation via Installation Flaw in Oracle Product Lifecycle Analytics 3.6.1

CVSS 3.1
8.4 high
EPSS
Published
()
Modified
AI analysis

Oracle Product Lifecycle Analytics 3.6.1, part of the Oracle Supply Chain suite, contains a vulnerability in its installation component that lets a low-privileged attacker who already has logon access to the server hosting the product compromise the entire application. Exploitation requires only local access with an ordinary low-privilege OS or application account, needs no user interaction, and is rated easily exploitable. Because the flaw changes scope, a successful attack can also significantly impact additional products beyond Product Lifecycle Analytics, yielding unauthorized creation, deletion, or modification of critical data as well as full read access to all data the product can reach. The issue is scored CVSS 3.1 8.4 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N), with high confidentiality and integrity impact but no availability impact. No public proof-of-concept exists and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE and upgrade Product Lifecycle Analytics from 3.6.1 to the patched release. Restrict local OS logon and interactive access on servers hosting the product to trusted administrators only, since exploitation requires a low-privilege local account. Audit the installation for weak file, directory, or service permissions left by the installer, and review logs for unauthorized data creation, modification, or deletion within the product and adjacent in-scope systems.

Affected
Oracle Product Lifecycle Analytics (Oracle Supply Chain)3.6.1
Estimated exposure
nichelikely hundreds to low thousands of on-prem enterprise deployments worldwide (clearly an estimate) — Oracle Product Lifecycle Analytics is a licensed, enterprise-grade supply chain analytics product typically installed on dedicated on-premises middleware/application servers within manufacturing and product companies, and no public install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.