Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Agile PLM 9.3.6 product contains a flaw in its security component that enables unauthenticated attackers who can reach the application via HTTP to bypass authorization controls and retrieve protected data. This bypass directly compromises confidentiality, allowing reading of any data accessible to the application, while integrity and availability remain unaffected. The vulnerability is identified as an authorization bypass (CWE-284).

Affected Systems

Oracle Corporation’s Agile PLM product, version 9.3.6, is the only version currently known to be affected. No other versions or related products are listed in the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 reflects high confidentiality impact with a low attack complexity, no privileges, and no user interaction, and an attack vector over the network via HTTP. The EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack path involves sending a crafted HTTP request to the vulnerable endpoint from an unauthenticated network host, causing the application to grant unauthorized access to protected data. The weakness is an authorization bypass (CWE-284).

Generated by OpenCVE AI on August 5, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or update to a fixed version of Oracle Agile PLM 9.3.6 that resolves the authorization bypass.
  • If a patch is not immediately available, restrict HTTP access to the Agile PLM instance to trusted IP ranges or require VPN, effectively blocking unauthenticated traffic from the internet.
  • Enable audit logging for sensitive API calls and regularly review logs for indications of unauthorized data access to detect any exploitation attempts early.

Generated by OpenCVE AI on August 5, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass in Oracle Agile PLM 9.3.6

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass in Oracle Agile PLM 9.3.6

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Leading to Confidential Data Exposure in Oracle Agile PLM 9.3.6

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Leading to Confidential Data Exposure in Oracle Agile PLM 9.3.6

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Plm
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:13:25.821Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61172

cve-icon Vulnrichment

Updated: 2026-07-23T15:38:02.689Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses