Oracle's July 2026 Critical Patch Update discloses CVE-2026-61174, a CVSS 9.0 vulnerability in Oracle Product Lifecycle Analytics that lets a local attacker fully compromise the product and reach beyond it.
What Is It
CVE-2026-61174 is a critical vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain, in the Installation Issues component. It is easily exploitable and allows an unauthenticated attacker with logon access to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, up to all data accessible to Oracle Product Lifecycle Analytics, as well as unauthorized read access to that same critical data.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.0 (CRITICAL), with a vector of AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. Two factors drive the severity: no privileges or user interaction are required, and the scope is changed (S:C), meaning attacks may significantly impact additional products beyond Oracle Product Lifecycle Analytics itself. Confidentiality and integrity impacts are both HIGH; there is no availability impact. Note that exploitation requires local logon to the executing infrastructure (AV:L), which constrains the attack surface but does not lower the potential damage.
There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the available source material.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Product Lifecycle Analytics (Oracle Supply Chain)
- Component: Installation Issues
- Affected version: 3.6.1
Patch Status
The fix is delivered as part of the Oracle Critical Patch Update for July 2026. Organizations running Oracle Product Lifecycle Analytics 3.6.1 should apply the corresponding CPU updates referenced in Oracle's security alert. No workaround is described in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61174: https://nvd.nist.gov/vuln/detail/CVE-2026-61174