Executive brief
Oracle Product Lifecycle Analytics is a supply chain management tool used to track and optimize product lifecycles. This vulnerability allows an unauthenticated attacker to remotely take over the application via a network connection, potentially compromising confidential supply chain data, disrupting operations, and enabling further attacks on connected systems.
Technical details
This is a critical remote code execution vulnerability in Oracle Product Lifecycle Analytics component of Oracle Supply Chain. The flaw is easily exploitable and requires no authentication or user interaction—an attacker with network access can send a specially crafted HTTP request to compromise the entire application. The vulnerability affects version 3.6.1 and allows complete takeover of the product, compromising confidentiality, integrity, and availability. Oracle has issued security advisories and patches should be available through official Oracle support channels.
Affected products
- Oracle Product Lifecycle Analytics 3.6.1
Timeline
- 2026-09-15: disclosed