Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Fri, 21 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Access via Oracle Product Lifecycle Analytics |
Thu, 20 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege Exploit of Oracle Product Lifecycle Analytics via Oracle Net | |
| Weaknesses | CWE-269 |
Thu, 20 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege Exploit of Oracle Product Lifecycle Analytics via Oracle Net | |
| Weaknesses | CWE-269 CWE-284 |
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Network Access Vulnerability in Oracle Product Lifecycle Analytics 3.6.1 | |
| Weaknesses | CWE-269 CWE-284 |
Wed, 19 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Network Access Vulnerability in Oracle Product Lifecycle Analytics 3.6.1 | |
| Weaknesses | CWE-269 CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle product Lifecycle Analytics |
|
| CPEs | cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle product Lifecycle Analytics |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:03:14.856Z
Updated: 2026-08-20T18:00:46.147Z
Reserved: 2026-08-04T22:06:34.614Z
Link: CVE-2026-71049
Updated: 2026-08-20T17:47:23.236Z
Status : Undergoing Analysis
Published: 2026-08-18T21:18:04.713
Modified: 2026-08-20T18:16:42.160
Link: CVE-2026-71049
No data.