Sceawere
Vulnerability Detail
CVE-2026-61178Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM Unauthenticated Takeover
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile Product Lifecycle Management for Process
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-07-21T22:18:49.523Z",
"pubdate": "2026-07-21T22:18:49.523Z",
"executiveSummary": "A critical security vulnerability exists within the installation component of Oracle Agile Product Lifecycle Management (PLM) for Process, specifically affecting version 6.2.4.\nThe vulnerability allows an unauthenticated, remote attacker to achieve full system compromise via network access over the TCP protocol.\nThe flaw possesses a CVSS 3.1 base score of 9.8, indicating the highest level of severity regarding Confidentiality, Integrity, and Availability impact.\nThe attack vector is characterized as network-based with low attack complexity, requiring no prior authentication or user interaction to successfully execute.\nSuccessful exploitation grants an attacker complete control over the affected application, posing a catastrophic risk to organizational supply chain data and operational continuity.",
"technicalDetails": "The vulnerability resides within the installation component of Oracle Agile Product Lifecycle Management for Process, specifically version 6.2.4. The nature of the flaw permits an unauthenticated threat actor to gain unauthorized access to the application via standard TCP network communication.\nFrom an architectural perspective, the vulnerability facilitates remote code execution or unauthorized administrative command injection during the application interaction process. Because the affected component handles critical installation and deployment functions, a successful exploit bypasses traditional security controls that would otherwise require valid credentials or session validation.\nThe attack flow proceeds as follows: 1) An attacker identifies a target instance of Oracle Agile PLM for Process version 6.2.4 accessible over the network. 2) The attacker crafts a malicious request targeted at the installation component via TCP. 3) Due to insufficient input validation or inadequate security controls within the installation routines, the application processes the request without authentication. 4) The attacker injects commands or payloads that execute with the privileges of the application process. 5) By successfully bypassing the intended authentication boundary, the attacker attains complete control, allowing for full unauthorized access to the system's data and configuration.\nThe impact is total, as the attacker achieves complete takeover of the application environment. This includes the ability to exfiltrate sensitive product lifecycle data, manipulate proprietary supply chain configurations, and disrupt the availability of the platform for legitimate users. Given that the vulnerability is categorized as having high impact on Confidentiality, Integrity, and Availability, the exploit effectively negates all security assurances provided by the application's native authentication and authorization mechanisms.\nThe lack of authentication requirements (PR:N) and user interaction (UI:N) makes this vulnerability particularly dangerous, as it can be exploited programmatically and at scale across environments where the installation interface remains exposed to the network. The scope (S:U) remains unchanged, indicating the impact is localized to the affected product environment, but the breadth of control achieved by the attacker essentially equates to total system ownership."
}