Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The description states that a low‑privilege local attacker who can log on to the host where Oracle Agile PLM runs may exploit this vulnerability to gain unrestricted access to the data stored in the application. The CVSS 3.1 score of 6.5 indicates a moderate to high level of risk, primarily affecting confidentiality; there is no loss of integrity or availability reported. Based on the high confidentiality impact indicated in the CVSS vector, it is inferred that an attacker could read, modify, or exfiltrate application data.

Affected Systems

Oracle Corporation’s Agile PLM product, specifically version 9.3.6, is susceptible to this issue. The vulnerability is documented in the security alert for July 2026 and applies exclusively to the 9.3.6 release; other versions are not listed as affected. Since the flaw’s scope is marked as changing, other Oracle Supply Chain applications could experience indirect impact if enterprise configurations overlap.

Risk and Exploitability

Any user possessing local or low‑privilege credentials on the system that hosts Oracle Agile PLM can exploit this weakness. Because the EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalogue, the likelihood of immediate exploitation appears low; however, the high confidentiality impact justifies prompt action. An attacker with local access could execute the flaw to read sensitive data, potentially leading to a full data breach if the application contains highly confidential information.

Generated by OpenCVE AI on August 4, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or upgrade to a version that includes the fix for Oracle Agile PLM 9.3.6
  • Restrict local logon access to the server hosting Oracle Agile PLM, ensuring only privileged accounts are permitted
  • Use firewalls or network segmentation to limit exposure of Oracle Agile PLM services to the minimal necessary threat surface

Generated by OpenCVE AI on August 4, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Access Leads to Data Compromise in Oracle Agile PLM 9.3.6

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Local Exploitation Allowing Full Data Access in Oracle Agile PLM 9.3.6
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Local Exploitation Allowing Full Data Access in Oracle Agile PLM 9.3.6
Weaknesses CWE-284
CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Plm
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:56:09.631Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61169

cve-icon Vulnrichment

Updated: 2026-07-23T18:21:25.861Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses