CVE-2026-61178: Critical severity Oracle Oracle Agile Product Lifecycle Management for Process vulnerability
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61178?
CVE-2026-61178 has a critical severity rating of 9.8.
How do I fix CVE-2026-61178?
To fix CVE-2026-61178, it is recommended to update the affected Oracle Agile Product Lifecycle Management for Process software to the latest version.
What are the potential impacts of CVE-2026-61178?
CVE-2026-61178 can allow an unauthenticated attacker to compromise Oracle Agile Product Lifecycle Management for Process through network access.
Which versions of Oracle Agile Product Lifecycle Management for Process are affected by CVE-2026-61178?
The affected version of Oracle Agile Product Lifecycle Management for Process is 6.2.4.
What type of attack is possible with CVE-2026-61178?
CVE-2026-61178 allows for an easily exploitable attack that can be carried out by an unauthenticated attacker with network access via TCP.