Junglewise Threat Intelligence

CVE-2026-83261: Oracle Product Lifecycle Analytics unauthenticated remote code execution

CVE-2026-83261 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle Product Lifecycle Analytics. Vendors: Oracle.

Executive brief

Oracle Product Lifecycle Analytics is a supply chain management tool used to track and optimize product lifecycles. This vulnerability allows an unauthenticated attacker to remotely take over the application via a network connection, potentially compromising confidential supply chain data, disrupting operations, and enabling further attacks on connected systems.

Technical details

This is a critical remote code execution vulnerability in Oracle Product Lifecycle Analytics component of Oracle Supply Chain. The flaw is easily exploitable and requires no authentication or user interaction—an attacker with network access can send a specially crafted HTTP request to compromise the entire application. The vulnerability affects version 3.6.1 and allows complete takeover of the product, compromising confidentiality, integrity, and availability. Oracle has issued security advisories and patches should be available through official Oracle support channels.

Affected products

  • Oracle Product Lifecycle Analytics 3.6.1

Timeline

  • 2026-09-15: disclosed

References

Related threats