← back

CVE-2026-83261

CRITICAL · 9.8
hype MIXED · 42 hack

New CVE, real vulnerability, but no working PoC, KEV absent, early chatter recycling NVD.

What: Unauthenticated remote code execution in Oracle Product Lifecycle Analytics 3.6.1 (Core component) via HTTP; CVSS 9.8 CRITICAL.

Why it matters: Published 24 hours ago with no PoC, no KEV listing, and no vendor advisory signal yet visible in social chatter. Early-stage disclosure; Oracle Supply Chain deployments are common attack surface. No confirmed in-the-wild exploitation reported.

Where it's seen: Bluesky posts summarizing NVD metadata; generic vulnerability aggregator links; no defender triage questions or PoC repositories yet.

RISK: CRITICAL — Unauthenticated RCE with CVSS 9.8; Oracle ecosystem wide exposure.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/16/2026, 4:03:08 AM

Description

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses