SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61184 2026-07-21

CVE-2026-61184: Critical Unauthenticated Flaw in Oracle Agile PLM for Process

"A critical, easily exploitable vulnerability in Oracle Agile Product Lifecycle Management for Process lets an unauthenticated network attacker read, alter, or delete critical product data over HTTP."

A critical, easily exploitable vulnerability in Oracle Agile Product Lifecycle Management for Process lets an unauthenticated network attacker read, alter, or delete critical product data over HTTP.

What Is It

CVE-2026-61184 is a vulnerability in the Oracle Agile Product Lifecycle Management (PLM) for Process product, part of Oracle Supply Chain, in the Product Quality Management component. Oracle rates it a CVSS 3.1 Base Score of 9.1 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.

The flaw is described as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. There is no requirement for privileges or user interaction.

Why It Matters

A successful attack can result in unauthorized creation, deletion, or modification of critical data, up to all data accessible to Oracle Agile PLM for Process, as well as unauthorized read access to critical or all accessible data. The CVSS breakdown reflects HIGH confidentiality and HIGH integrity impact (availability impact is rated NONE).

Because exploitation requires no authentication and only network access over HTTP, the barrier to attack is low (attack complexity: LOW; exploitability score: 3.9), making internet- or network-reachable instances a significant risk.

What's Vulnerable

Patch Status

Oracle addresses this issue in its Critical Patch Update for July 2026. Administrators should consult the Oracle Critical Patch Update advisory (linked below) and apply the relevant fixes. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources