Junglewise Threat Intelligence

CVE-2026-61181: Oracle Agile Product Lifecycle Management for Process data compromise in Product Quality Management

CVE-2026-61181 · Severity: high · CVSS 7.6 · Published 2026-07-21

Technologies: Oracle Agile Product Lifecycle Management for Process. Vendors: Oracle.

Executive brief

Oracle Agile Product Lifecycle Management for Process, a tool used by manufacturers to manage product data and quality, contains a security vulnerability in its Product Quality Management component. An attacker with low-level access to the system could trick another user into performing an action that grants the attacker unauthorized access to sensitive business data. This could lead to the theft of critical information or the unauthorized modification of product quality records, potentially impacting other integrated business systems.

Technical details

A vulnerability in the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process (version 6.2.4) allows for a scope-changing attack, likely involving Cross-Site Scripting (XSS) or a similar injection flaw given the requirement for user interaction (UI:R) and the scope change (S:C). A low-privileged attacker can exploit this over the network via HTTP. Successful exploitation can result in high confidentiality impact, allowing access to all accessible data, and low integrity impact, allowing unauthorized updates or deletions. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile Product Lifecycle Management for Process 6.2.4

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
  • 2026-07-21: disclosed

References

Related threats