Sceawere

Vulnerability Detail

CVE-2026-71050UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Product Lifecycle Analytics Installation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Product Lifecycle Analytics
Attack Type
Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-08-18T21:18:04.830Z",
  "pubdate": "2026-08-18T21:18:04.830Z",
  "executiveSummary": "An installation-related security vulnerability affects the Oracle Product Lifecycle Analytics product within Oracle Supply Chain, specifically targeting version 3.6.1. This remotely exploitable flaw allows an authenticated attacker with high privileges and network access via Oracle Net to compromise the integrity and confidentiality of the targeted system. Successful exploitation of this vulnerability has a scope-changing impact, meaning that attacks may significantly affect additional products beyond the primary vulnerable component. The primary risk implications include unauthorized creation, deletion, modification, and complete access to critical data or all accessible data within Oracle Product Lifecycle Analytics. The vulnerability carries a CVSS 3.1 Base Score of 8.7, indicating severe potential impact on both confidentiality and integrity while maintaining no availability impact. Exploitation conditions require network connectivity, low attack complexity, and high privileges, but do not require user interaction.",
  "technicalDetails": "The vulnerability resides within the Installation Issues component of Oracle Product Lifecycle Analytics version 3.6.1. The root cause stems from insecure installation procedures or misconfigurations within the deployment framework that fail to enforce strict access controls or validate administrative configurations properly during setup. Exploitation of this vulnerability requires the attacker to possess high privileges within the environment and network access utilizing the Oracle Net protocol. Because the attack vector is network-based (AV:N), the adversary does not require physical access to the host operating system, relying instead on remote connectivity protocols native to the Oracle database and application architecture. The attack flow initiates when a highly privileged threat actor leverages Oracle Net to interact with the vulnerable installation component. Due to the scope-changing (S:C) nature of the vulnerability, successful execution of malicious payloads is not strictly contained within the boundaries of Oracle Product Lifecycle Analytics; rather, it extends the attack surface to impact additional collateral products and shared underlying resources. The payload behavior facilitates unauthorized administrative interactions, bypassing intended security boundaries to grant the attacker capabilities to execute unauthorized data modification, creation, and deletion operations (I:H). Furthermore, the adversary achieves complete or critical confidentiality breaches (C:H) by gaining unauthorized read access to sensitive corporate data stored within or accessible by Oracle Product Lifecycle Analytics. The technical prerequisites demand that the attacker has already authenticated with elevated privileges, subsequently leveraging the flawed installation mechanics to escalate their data access scope and compromise the wider system architecture without triggering availability disruptions (A:N)."
}
CVE-2026-71050: Oracle Product Lifecycle Analytics Installation Vulnerability (HIGH Severity, CVSS: 8.7) - Sceawere