Executive brief
A vulnerability in Oracle's supply chain management software could allow an authorized user with low-level permissions to take full control of the Product Quality Management system. This software is used by businesses to manage product specifications and quality standards throughout the manufacturing lifecycle. A successful exploit could lead to the theft of sensitive product data, unauthorized changes to quality records, or a total disruption of the supply chain management process.
Technical details
A vulnerability exists in the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the application. While the specific CWE is not explicitly detailed in the advisory, the impact is rated as high for confidentiality, integrity, and availability, potentially resulting in a complete takeover of the affected component. The attack does not require user interaction. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Agile Product Lifecycle Management for Process 6.2.4
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-61179
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update