A critical, easily exploitable vulnerability in Oracle Product Lifecycle Analytics 3.6.1 lets unauthenticated remote attackers access sensitive data and cause partial service disruption, with impact that can spread beyond the vulnerable product.
What Is It
CVE-2026-61175 is a critical vulnerability (CVSS 3.1 base score 9.3) in the Oracle Product Lifecycle Analytics product, part of Oracle Supply Chain. The flaw sits in the Installation Issues component. According to Oracle's advisory, an unauthenticated attacker with network access via HTTP can exploit it easily to compromise Oracle Product Lifecycle Analytics. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and a changed scope.
Why It Matters
Successful exploitation can result in unauthorized access to critical data, up to complete access to all data accessible to Oracle Product Lifecycle Analytics, along with the ability to cause a partial denial of service. Critically, the vulnerability carries a scope change: while the flaw resides in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products. The combination of no authentication, low complexity, and network reachability makes this an attractive target.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Product Lifecycle Analytics (Oracle Supply Chain)
- Component: Installation Issues
- Affected version: 3.6.1
Patch Status
Oracle addressed this issue as part of its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (July 2026) and apply the relevant fixes. This CVE does not appear in the supplied CISA KEV data, so there is no confirmation of active exploitation in the source material provided.