Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 19 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege HTTP Exploitation Granting Unauthorized Access in Oracle Product Lifecycle Analytics 3.6.1 |
Wed, 19 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege HTTP Exploitation Granting Unauthorized Access in Oracle Product Lifecycle Analytics 3.6.1 | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L). | |
| First Time appeared |
Oracle
Oracle product Lifecycle Analytics |
|
| CPEs | cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle product Lifecycle Analytics |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:03:14.525Z
Updated: 2026-08-19T12:55:08.786Z
Reserved: 2026-08-04T22:06:34.614Z
Link: CVE-2026-71048
Updated: 2026-08-19T12:09:42.741Z
Status : Awaiting Analysis
Published: 2026-08-18T21:18:04.600
Modified: 2026-08-20T13:08:14.613
Link: CVE-2026-71048
No data.