Junglewise Threat Intelligence

CVE-2026-61175: Oracle Product Lifecycle Analytics security bypass in Installation Issues

CVE-2026-61175 · Severity: critical · CVSS 9.3 · Published 2026-07-21

Technologies: Oracle Product Lifecycle Analytics. Vendors: Oracle.

Executive brief

Oracle Product Lifecycle Analytics, a tool used by businesses to analyze supply chain and product data, contains a critical security vulnerability in its installation component. An unauthorized attacker could exploit this over the network to gain full access to sensitive business data and potentially disrupt the availability of the service. This flaw is particularly serious because it can impact other integrated systems beyond the analytics platform itself.

Technical details

This vulnerability exists within the 'Installation Issues' component of Oracle Product Lifecycle Analytics version 3.6.1. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit results in a 'Scope Change' (S:C), meaning the impact can extend to other products beyond the immediate analytics environment. Successful exploitation grants unauthorized access to all accessible data (Confidentiality: High) and allows the attacker to cause a partial denial of service (Availability: Low). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Product Lifecycle Analytics 3.6.1

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats