Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
History

Fri, 21 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Oracle Product Lifecycle Analytics

Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Exploit of Oracle Product Lifecycle Analytics via Oracle Net
Weaknesses CWE-269

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Exploit of Oracle Product Lifecycle Analytics via Oracle Net
Weaknesses CWE-269
CWE-284

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Access Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-269
CWE-284

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Access Vulnerability in Oracle Product Lifecycle Analytics 3.6.1
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle product Lifecycle Analytics
CPEs cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Lifecycle Analytics
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2026-08-18T21:03:14.856Z

Updated: 2026-08-20T18:00:46.147Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71049

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:23.236Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-18T21:18:04.713

Modified: 2026-08-20T18:16:42.160

Link: CVE-2026-71049

cve-icon Redhat

No data.