Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Agile PLM 9.3.6 contains a flaw in the Folders, Files & Attachments component that allows an unauthenticated attacker who can reach the HTTP interface to bypass normal access controls. The vulnerability is a classic information exposure (CWE‑200). An attacker must trick a user other than themselves into interacting with a specially crafted artifact; once that interaction occurs, the attacker can read any critical data stored in the system or gain full access to all data that the user is able to see. The flaw increases the confidentiality impact, as stated in the CVSS 3.1 vector, and does not affect integrity or availability.

Affected Systems

The only version explicitly listed as impacted is Oracle Agile PLM 9.3.6. All installations of that version, regardless of deployment environment, should be considered at risk.

Risk and Exploitability

The CVSS base score of 6.5 represents a medium severity risk. An EPSS score of less than 1% indicates that, as of now, automated exploitation is unlikely; however, the need for human interaction means that social‑engineering attempts may still be employed. The issue is not included in the CISA KEV catalog, further suggesting that widespread exploitation has not been documented. Exploitation would require an attacker to hold HTTP network access to the target instance and to entice a user into opening a malicious attachment or link that triggers the vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 05:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Block untrusted IP addresses or require VPN access before allowing HTTP traffic to Oracle Agile PLM
  • Configure the application to enforce authentication and, if possible, multi‑factor authentication for all file and folder operations
  • Educate users to verify the source of attachments and avoid opening files from unfamiliar senders
  • Configure logging and monitoring to detect anomalous download or file access patterns

Generated by OpenCVE AI on August 4, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Oracle Agile PLM 9.3.6 Unauthenticated Information Exposure

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Agile PLM Allows Data Exfiltration

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Agile PLM Allows Data Exfiltration

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:57.318Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47009

cve-icon Vulnrichment

Updated: 2026-07-23T14:56:32.179Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:06.373

Modified: 2026-07-31T15:10:57.357

Link: CVE-2026-47009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor