Impact
The description states that a low‑privilege local attacker who can log on to the host where Oracle Agile PLM runs may exploit this vulnerability to gain unrestricted access to the data stored in the application. The CVSS 3.1 score of 6.5 indicates a moderate to high level of risk, primarily affecting confidentiality; there is no loss of integrity or availability reported. Based on the high confidentiality impact indicated in the CVSS vector, it is inferred that an attacker could read, modify, or exfiltrate application data.
Affected Systems
Oracle Corporation’s Agile PLM product, specifically version 9.3.6, is susceptible to this issue. The vulnerability is documented in the security alert for July 2026 and applies exclusively to the 9.3.6 release; other versions are not listed as affected. Since the flaw’s scope is marked as changing, other Oracle Supply Chain applications could experience indirect impact if enterprise configurations overlap.
Risk and Exploitability
Any user possessing local or low‑privilege credentials on the system that hosts Oracle Agile PLM can exploit this weakness. Because the EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalogue, the likelihood of immediate exploitation appears low; however, the high confidentiality impact justifies prompt action. An attacker with local access could execute the flaw to read sensitive data, potentially leading to a full data breach if the application contains highly confidential information.
OpenCVE Enrichment