Junglewise Threat Intelligence

CVE-2026-61174: Oracle Product Lifecycle Analytics compromise via Installation Issues

CVE-2026-61174 · Severity: critical · CVSS 9 · Published 2026-07-21

Technologies: Oracle Product Lifecycle Analytics. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Product Lifecycle Analytics, a tool used by businesses to analyze supply chain and product data. An attacker who has gained access to the underlying server infrastructure can exploit installation-related issues to gain full control over the application's data. This could lead to the theft, deletion, or modification of sensitive corporate product information and potentially impact other connected systems.

Technical details

This vulnerability stems from installation-related issues within Oracle Product Lifecycle Analytics version 3.6.1. It is classified as a local attack because it requires the attacker to have logon access to the infrastructure where the software executes. Despite being a local attack, it requires no prior privileges (PR:N) and no user interaction (UI:N). The exploit results in a scope change (S:C), meaning the attacker can potentially impact components beyond the immediate application. Successful exploitation grants full confidentiality and integrity access, allowing for the unauthorized creation, deletion, or modification of all data accessible to the application.

Affected products

  • Oracle Product Lifecycle Analytics 3.6.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 CPU.
  • 2026-07-21: advisory: NVD published the CVE record.

References

Related threats