Sceawere

Vulnerability Detail

CVE-2026-61184Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM Unauthorized Access

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Agile Product Lifecycle Management for Process
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:50.233Z",
  "pubdate": "2026-07-21T22:18:50.233Z",
  "executiveSummary": "A critical security vulnerability exists within the Product Quality Management component of Oracle Agile Product Lifecycle Management (PLM) for Process, specifically affecting version 6.2.4.\nThe vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to the application via HTTP, leading to significant compromises in data confidentiality and integrity.\nAn attacker can perform unauthorized creation, deletion, or modification of critical business data, effectively allowing complete unauthorized access to all data accessible within the application.\nThe vulnerability is classified as easily exploitable, requiring no prior authentication, user interaction, or specific privileges, which significantly increases the risk profile for organizations utilizing the affected software.\nThe vulnerability carries a CVSS 3.1 Base Score of 9.1, reflecting its severity in terms of its potential to undermine the core security posture of the supply chain management environment.",
  "technicalDetails": "The vulnerability resides within the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. It is characterized as a flaw that permits unauthenticated access over a network via the HTTP protocol.\nThe attack vector is characterized by its simplicity: an attacker utilizes network connectivity to interact with the target application without the need for credentials or established session tokens. This indicates a failure in access control mechanisms or improper validation of incoming HTTP requests before processing them within the application's business logic layers.\nExploitation occurs when an attacker crafts malicious HTTP requests directed at the vulnerable component. Because the system fails to verify the identity of the requester, the application processes these requests with the authority of a privileged user or service account. This bypass allows the attacker to execute administrative or data-centric functions that should be restricted.\nThe attack flow proceeds as follows: 1) The attacker identifies the target endpoint associated with the Product Quality Management component. 2) The attacker submits manipulated HTTP requests to these endpoints, bypassing authentication filters or exploiting insecure direct object references. 3) The application, failing to authenticate the origin, executes the requested operations, such as record modification, deletion, or data extraction. 4) The attacker receives the requested data or receives confirmation of the unauthorized modifications, completing the compromise.\nThe post-exploitation impact is severe. Since the vulnerability permits both the unauthorized modification and unauthorized access to data, an attacker can manipulate quality control records, delete essential audit trails, or exfiltrate sensitive proprietary product information. The integrity impact is high, as the application cannot guarantee the veracity of the processed data, and the confidentiality impact is high, as unauthorized entities can view all accessible information. Given that this is a PLM system, such impacts can result in downstream supply chain disruptions or regulatory non-compliance."
}
CVE-2026-61184: Oracle Agile PLM Unauthorized Access (CRITICAL Severity, CVSS: 9.1) - Sceawere