Sceawere

Vulnerability Detail

CVE-2026-61183Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Critical RCE in Oracle Agile PLM

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Agile Product Lifecycle Management for Process
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:50.110Z",
  "pubdate": "2026-07-21T22:18:50.110Z",
  "executiveSummary": "This vulnerability affects the Reporting component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. It is classified as a critical security flaw that enables an unauthenticated, remote attacker to gain full control over the affected system.\nThe vulnerability allows for complete system compromise, impacting Confidentiality, Integrity, and Availability. Because the attack vector is network-accessible and requires no authentication, it presents an extreme risk to organizational infrastructure.\nThe flaw stems from insufficient security controls within the reporting architecture, permitting unauthorized actors to execute arbitrary actions or commands. Successful exploitation grants the attacker extensive privileges, essentially resulting in a total takeover of the application environment.\nGiven the high CVSS 3.1 base score of 9.8, immediate remediation is required to prevent unauthorized data exfiltration, service disruption, and potential lateral movement within the network.",
  "technicalDetails": "The vulnerability resides within the Reporting component of the Oracle Agile Product Lifecycle Management for Process software suite, specifically affecting version 6.2.4. The architecture fails to properly sanitize or validate input delivered via HTTP requests, creating a pathway for remote code execution or unauthorized system manipulation.\nThe attack vector is identified as network-based, meaning any attacker with reach to the target's HTTP/HTTPS interface can initiate the exploit. Because the vulnerability does not require authentication or user interaction (AV:N/AC:L/PR:N/UI:N), the barrier to entry is minimal, allowing for automated exploitation attempts by malicious actors.\nThe attack flow initiates when a crafted HTTP request is sent to the vulnerable Reporting endpoint. By bypassing the application's authentication mechanisms, the attacker forces the underlying component to process malicious data. This data is likely processed in a context that allows the attacker to execute operating system commands or inject arbitrary code into the application runtime.\nUpon successful execution, the payload may allow the attacker to assume the identity of the application service account. Given the typical deployment patterns of Oracle Agile PLM, this account often possesses significant privileges over the application server and its associated database. This provides the attacker with full control over the application, enabling them to read sensitive product lifecycle data, modify business-critical engineering configurations, or disrupt core system operations.\nThe impact is categorized as total (C:H/I:H/A:H), as the attacker can achieve a full takeover. Post-exploitation activities may include the deployment of persistent backdoors, the escalation of privileges to the host operating system, and the eventual compromise of the broader production environment where the Agile PLM instance is hosted. The lack of requisite privileges or complexity in the exploit string makes this a high-probability event for exposed, internet-facing installations."
}
CVE-2026-61183: Critical RCE in Oracle Agile PLM (CRITICAL Severity, CVSS: 9.8) - Sceawere