Junglewise Threat Intelligence

CVE-2026-61180: Oracle Agile PLM for Process takeover in Product Quality Management

CVE-2026-61180 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Agile Product Lifecycle Management for Process. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's supply chain management software used for managing product quality and lifecycles. An attacker with basic user access can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive product data, unauthorized changes to quality management processes, or a complete shutdown of the application.

Technical details

A vulnerability in the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process (version 6.2.4) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected component. While the specific CWE is not detailed in the advisory, the impact and vector suggest a significant authorization or input validation failure. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Agile Product Lifecycle Management for Process 6.2.4

Timeline

  • 2026-07-21: disclosed: Initial disclosure in Oracle Critical Patch Update
  • 2026-07-21: advisory: NVD publication date

References

Related threats