Junglewise Threat Intelligence

CVE-2026-61185: Oracle Agile Product Lifecycle Management for Process information disclosure in Installation

CVE-2026-61185 · Severity: high · CVSS 7.4 · Published 2026-07-21

Technologies: Oracle Agile Product Lifecycle Management for Process. Vendors: Oracle.

Executive brief

A vulnerability exists in the installation component of Oracle's supply chain management software. An attacker who is on the same local network as the server can gain unauthorized access to sensitive business data. This could lead to a significant breach of proprietary product lifecycle information and potentially impact other connected systems.

Technical details

A vulnerability in the Installation component of Oracle Agile Product Lifecycle Management for Process (version 6.2.4) allows an unauthenticated attacker with access to the physical communication segment (adjacent network) to compromise the application. The exploit is characterized as easily exploitable and results in a scope change, meaning the impact can extend beyond the immediate application to other integrated products. Successful exploitation results in a high impact on confidentiality, allowing unauthorized access to critical data or complete access to all data accessible by the PLM software. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile Product Lifecycle Management for Process 6.2.4

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update

References

Related threats