Junglewise Threat Intelligence

CVE-2026-61176: Oracle Product Lifecycle Analytics security bypass in Installation Issues

CVE-2026-61176 · Severity: medium · CVSS 6.7 · Published 2026-07-21

Technologies: Oracle Product Lifecycle Analytics. Vendors: Oracle.

Executive brief

Oracle Product Lifecycle Analytics, a tool used for analyzing supply chain and product data, contains a security vulnerability in its installation component. A high-privileged user with network access can exploit this flaw to gain full control over the application's data, allowing them to view, modify, or delete sensitive information. Additionally, an attacker could cause a partial disruption of the service, impacting business operations and data integrity.

Technical details

This vulnerability exists in the 'Installation Issues' component of Oracle Product Lifecycle Analytics version 3.6.1. It is classified as an easily exploitable flaw that requires high privileges (PR:H) and network access via HTTP (AV:N). An attacker with these credentials can achieve full confidentiality and integrity compromise (C:H/I:H) by gaining unauthorized access to or modifying critical data within the application. The vulnerability also allows for a partial impact on availability (A:L), potentially leading to a partial denial of service. The issue was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Product Lifecycle Analytics 3.6.1

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
  • 2026-07-21: disclosed: CVE-2026-61176 was published to the NVD.

References

Related threats