Oracle's July 2026 Critical Patch Update discloses CVE-2026-61178, a critical (CVSS 9.8) flaw allowing an unauthenticated remote attacker to fully compromise Oracle Agile Product Lifecycle Management for Process.
What Is It
CVE-2026-61178 is a vulnerability in the Installation component of Oracle Agile Product Lifecycle Management (PLM) for Process, part of the Oracle Supply Chain suite. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise the product. Successful exploitation can result in complete takeover of the affected system.
The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network reachability, no authentication, and low attack complexity makes this flaw trivial to exploit at scale against exposed instances. Because successful attacks yield full takeover of the product, not just data disclosure, an attacker can read, alter, and destroy data or disrupt operations. As a supply chain / product lifecycle platform, a compromised instance can expose sensitive product and process data.
What's Vulnerable
- Product: Oracle Agile Product Lifecycle Management for Process (Oracle Supply Chain)
- Component: Installation
- Affected version: 6.2.4
- Vendor: Oracle Corporation
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Administrators should apply the fixes referenced in the Oracle security alert. There is no CISA KEV entry supplied for this CVE, so no confirmed active exploitation is indicated in the source material; given the 9.8 severity and unauthenticated exploitability, patching should be treated as urgent.