Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Agile PLM 9.3.6 has an unauthenticated network vulnerability that can be exploited via HTTP requests without any authentication. Successful exploitation can give an attacker full control of the application, enabling disclosure of confidential data, tampering with operational data, and denial of service. The flaw is classified as an unauthorized access and authentication weakness (CWE‑284 and CWE‑306) and carries a CVSS 3.1 Base Score of 9.8, indicating complete loss of confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Oracle Corporation’s Agile PLM product version 9.3.6. No other versions or products are listed as impacted by the current CNA data.

Risk and Exploitability

The CVSS vector indicates an attacker with network access can exploit the flaw easily (low attack complexity, no user interaction). The EPSS score of less than 1% shows a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. However, the high severity combined with the lack of authentication requirements means that exposed instances are at high risk of immediate exploitation if the system is reachable over the network.

Generated by OpenCVE AI on August 4, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a version where the issue is fixed
  • If a patch is not yet available, restrict external HTTP access to Oracle Agile PLM by blocking or limiting traffic from untrusted networks
  • Enforce network segmentation and firewall rules so that only trusted internal hosts can reach the application
  • Enable audit logging for all authentication and administrative actions to detect any unauthorized activity

Generated by OpenCVE AI on August 4, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Takeover of Oracle Agile PLM 9.3.6

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Takeover of Oracle Agile PLM 9.3.6

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability Allowing Full System Takeover in Oracle Agile PLM 9.3.6

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability Allowing Full System Takeover in Oracle Agile PLM 9.3.6

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:56:00.131Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61167

cve-icon Vulnrichment

Updated: 2026-07-23T18:23:25.290Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function