Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

According to the CVE description, the Oracle Agile PLM 9.3.6 product contains a vulnerability that enables a low‑privileged attacker with network access via HTTP to compromise the application. The flaw is an improper access control weakness (CWE‑284) that can be exploited easily, giving an attacker the ability to take over the system. Successful exploitation would undermine confidentiality, integrity, and availability of the application, effectively allowing an attacker to control Oracle Agile PLM.

Affected Systems

The affected product is Oracle Agile PLM, version 9.3.6, part of the Oracle Supply Chain Management suite.

Risk and Exploitability

The vulnerability can be exploited over HTTP, giving a network attacker with low privileges the ability to compromise the application. The EPSS score is below 1 %, indicating a very low but non‑zero probability of widespread exploitation. While the vulnerability is not listed in the CISA KEV catalog, the CVSS v3.1 base score of 8.8 reflects a high‑impact risk for exposed installations where the User and User Group component is reachable over the network.

Generated by OpenCVE AI on August 4, 2026 at 16:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Oracle’s latest security patch or upgrade to a newer supported version of Agile PLM as soon as it becomes available
  • Restrict HTTP traffic to the application by placing it behind a VPN or firewall, allowing only trusted administrative IP ranges
  • Enforce the principle of least privilege for all user accounts, ensuring that only authorized users have access to the User and User Group component

Generated by OpenCVE AI on August 4, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Exploitation in Oracle Agile PLM 9.3.6

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Exploitation in Oracle Agile PLM 9.3.6

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Leading to Full Compromise of Oracle Agile PLM 9.3.6
Weaknesses CWE-269

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Leading to Full Compromise of Oracle Agile PLM 9.3.6
Weaknesses CWE-269

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:59.323Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61166

cve-icon Vulnrichment

Updated: 2026-07-23T18:24:03.324Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses