CVE-2026-61188
HIGH · 7.5No KEV, no PoC, no advisory urgency; recycled vulnerability announcement chatter only.
What: Oracle Agile Product Lifecycle Management for Process 6.2.4 allows low-privileged network attackers to gain full system compromise via HTTP; CVSS 7.5 HIGH.
Why it matters: CVE published 11 days ago with no KEV listing, no confirmed PoC, and no urgent vendor advisories in the chatter. Posts are in Hebrew and Russian on smaller platforms, suggesting repackaged vulnerability announcements rather than active exploitation signals or coordinated defender response.
Where it's seen: Low-engagement social posts on alternative platforms (Bluesky) linking to non-canonical sources; no mainstream security researcher coverage, no vendor emergency patches, no defender triage questions observed.
RISK: MODERATE — Supply chain component; 7.5 CVSS; requires low privilege and network access; no exploitation evidence yet.
Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- High
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Affected versions
- oracle/agile_product_lifecycle_management_for_process
- 6.2.4