Sceawere

Vulnerability Detail

CVE-2026-71051UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Product Lifecycle Analytics Takeover Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Product Lifecycle Analytics
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-18T21:18:04.940Z",
  "pubdate": "2026-08-18T21:18:04.940Z",
  "executiveSummary": "A vulnerability exists within the Installation Issues component of Oracle Product Lifecycle Analytics version 3.6.1, part of Oracle Supply Chain. This security flaw is classified as easily exploitable, allowing a low-privileged threat actor with valid logon access to the underlying infrastructure where the application executes to achieve a complete system compromise.\nThe inherent risks associated with this vulnerability are severe, yielding a CVSS 3.1 Base Score of 8.8 with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The scope of the vulnerability extends beyond the immediate application, demonstrating a scope change (S:C) that can significantly impact additional products residing within the shared infrastructure.\nSuccessful exploitation of this flaw grants the attacker the ability to execute unauthorized actions resulting in the complete takeover of Oracle Product Lifecycle Analytics. The attack requires local access (AV:L), low attack complexity (AC:L), and low privileges (PR:L), while requiring no user interaction (UI:N). The resulting impact encompasses total loss of confidentiality, integrity, and availability (C:H/I:H/A:H) across the affected target environment, presenting critical operational and security risks to enterprise deployments.",
  "technicalDetails": "The vulnerability resides in the Installation Issues component of Oracle Product Lifecycle Analytics, specifically affecting version 3.6.1. The root cause stems from improper security controls and misconfigurations during the installation or operational execution phase within the hosting infrastructure. Because the flaw originates in the installation layer, underlying file permissions, directory structures, or execution contexts likely fail to enforce strict separation of duties or least privilege principles.\nExploitation of this vulnerability requires the attacker to already possess authenticated logon access to the host infrastructure executing Oracle Product Lifecycle Analytics. Given the low privilege requirement (PR:L) and low attack complexity (AC:L), an adversary with standard user credentials can leverage insecure installation artifacts, overly permissive file system permissions, or unvalidated configuration pathways to escalate privileges or manipulate runtime execution flows.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes an interactive or programmatic session on the target infrastructure hosting the vulnerable software. Second, leveraging the predictable or insecurely configured installation parameters inherent to the Installation Issues component, the attacker interacts with local application binaries, scripts, or configuration files. Third, due to inadequate access controls or improper handling of system resources during installation and runtime, the attacker injects malicious payloads, modifies critical application components, or hijacks execution handles.\nAs the application processes these manipulated components, the attacker executes arbitrary code within the security context of the application or the hosting service. Because of the broadened security scope (S:C), the compromise is not strictly contained to the initial application boundary; the escalation vector permits lateral movement or systemic interference with co-located products and services managed within the same infrastructure tier. The post-exploitation phase culminates in a full takeover of Oracle Product Lifecycle Analytics, providing the attacker with unrestricted reading, modification, and destruction capabilities over sensitive data assets, application logic, and system availability."
}
CVE-2026-71051: Oracle Product Lifecycle Analytics Takeover Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere