Sceawere
Vulnerability Detail
CVE-2026-61174Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Lifecycle Analytics Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Product Lifecycle Analytics
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 9.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-07-21T22:18:49.170Z",
"pubdate": "2026-07-21T22:18:49.170Z",
"executiveSummary": "A critical vulnerability exists in Oracle Product Lifecycle Analytics version 3.6.1 within the Installation Issues component. The flaw allows an unauthenticated attacker, who has already gained logon access to the underlying infrastructure, to compromise the integrity and confidentiality of the application. The vulnerability carries a CVSS 3.1 base score of 9.0, reflecting the severity of the potential impact.\nThe vulnerability is characterized by a scope change (S:C), meaning a compromise of the Oracle Product Lifecycle Analytics installation can escalate to affect other products or components residing on the same infrastructure. Successful exploitation grants the attacker unauthorized access to, or the ability to modify and delete, sensitive data stored within the product ecosystem. Because the attack requires local access (AV:L) but no user interaction or authentication (PR:N/UI:N), it poses a significant threat to organizational data security, necessitating immediate attention to infrastructure hardening and access control policies.",
"technicalDetails": "The vulnerability identified in Oracle Product Lifecycle Analytics version 3.6.1 stems from inadequate security controls during the installation process, classified under the Installation Issues component. This flaw permits an attacker with local, unauthenticated logon access to the host infrastructure to manipulate the application's environment or configuration.\nThe technical exploitation flow involves an attacker leveraging their local presence on the system to target the Oracle Product Lifecycle Analytics installation. Since the vulnerability does not require authentication (PR:N) or specific user interaction (UI:N), the attacker can execute unauthorized commands or access sensitive files directly from the local environment. Given the 'Scope Changed' (S:C) nature of the vulnerability, the attack surface extends beyond the application itself, potentially allowing the attacker to bypass isolation boundaries and interface with the underlying OS or other co-hosted services.\nUpon gaining access, the attacker can perform unauthorized Create, Read, Update, and Delete (CRUD) operations on the data handled by the application. Because the impact vector includes high confidentiality (C:H) and high integrity (I:H) loss, the attacker effectively gains full control over the application's data layer. This includes the ability to exfiltrate critical enterprise data or modify existing records to facilitate further malicious activity or persist within the system.\nThe exploit relies on the low complexity (AC:L) of the installation configuration, suggesting that the application may inadvertently expose sensitive configuration files, scripts, or service accounts with excessive permissions during or after the deployment phase. Once an attacker accesses the local infrastructure, they can interact with these exposed components to escalate their privileges or manipulate the application's execution logic. Post-exploitation impact is severe, as the attacker can effectively masquerade as the application service to perform unauthorized transactions, alter system configurations, or compromise connected databases and downstream dependencies. The vulnerability highlights a failure in the principle of least privilege, as the application likely operates with excessive system-level permissions that are then exploitable by any local user."
}