CVE-2026-83261
CRITICAL · 9.8New CVE, real vulnerability, but no working PoC, KEV absent, early chatter recycling NVD.
What: Unauthenticated remote code execution in Oracle Product Lifecycle Analytics 3.6.1 (Core component) via HTTP; CVSS 9.8 CRITICAL.
Why it matters: Published 24 hours ago with no PoC, no KEV listing, and no vendor advisory signal yet visible in social chatter. Early-stage disclosure; Oracle Supply Chain deployments are common attack surface. No confirmed in-the-wild exploitation reported.
Where it's seen: Bluesky posts summarizing NVD metadata; generic vulnerability aggregator links; no defender triage questions or PoC repositories yet.
RISK: CRITICAL — Unauthenticated RCE with CVSS 9.8; Oracle ecosystem wide exposure.
Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High