Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exploitable flaw exists in the Security component of Oracle Agile PLM 9.3.6. The weakness involves insufficient privilege checks and access controls (CWE-269, CWE-284, CWE-287, and CWE-306), allowing a low‑privileged attacker who can reach the server over HTTP to compromise the application, resulting in a complete takeover that exposes the system’s data and control functions. The impact includes total loss of confidentiality, integrity, and availability as indicated by the CVSS Base Score of 8.8.

Affected Systems

Oracle Corporation’s Oracle Agile PLM product, version 9.3.6, is affected. The weakness is within the Security component of the application.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.8 indicates the vulnerability is exploitable over the network with low attacker privileges and no user interaction. The EPSS score of less than 1% suggests exploitation is currently considered uncommon, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is HTTP network access, where an attacker can inject malformed requests to trigger the bug and gain full control of the application.

Generated by OpenCVE AI on August 4, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch for Agile PLM 9.3.6 that addresses the security component flaw
  • Restrict HTTP access to the Agile PLM server using firewall or ACLs to limit exposure to trusted IP addresses
  • Audit and disable any unnecessary HTTP services or endpoints that could be leveraged by the vulnerability

Generated by OpenCVE AI on August 4, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Remote Exploit Enables Full Takeover of Oracle Agile PLM

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Exploit Enables Full Takeover of Oracle Agile PLM

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title HTTP Exploit Enables Full Takeover of Oracle Agile PLM 9.3.6

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title HTTP Exploit Enables Full Takeover of Oracle Agile PLM 9.3.6

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:56:08.869Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61168

cve-icon Vulnrichment

Updated: 2026-07-23T18:22:31.219Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function