Oracle's July 2026 Critical Patch Update discloses CVE-2026-61183, a CVSS 9.8 flaw that lets an unauthenticated attacker fully compromise Oracle Agile Product Lifecycle Management for Process over the network.
What Is It
CVE-2026-61183 is a critical vulnerability in the Reporting component of Oracle Agile Product Lifecycle Management (PLM) for Process, part of the Oracle Supply Chain family. The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. According to Oracle, successful attacks can result in a complete takeover of Oracle Agile PLM for Process.
The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of remote, unauthenticated exploitation and full system takeover makes this among the most severe vulnerability classes. Because no credentials or user interaction are needed, any network-reachable instance is exposed to attackers who can reach it over HTTP. PLM systems typically hold sensitive product, supply chain, and formulation data, so a takeover has direct confidentiality, integrity, and availability consequences.
What's Vulnerable
- Product: Oracle Agile Product Lifecycle Management for Process (Oracle Corporation)
- Component: Reporting
- Affected version: 6.2.4
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running the affected 6.2.4 release should apply the fixes referenced in Oracle's advisory as a priority. No CISA KEV entry confirming active exploitation was supplied with this record; the NVD status is "Received."