Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Agile PLM 9.3.6 is affected by a high‑severity vulnerability in its security component that can be triggered over HTTP without authentication. The flaw permits attackers to compromise the application, effectively allowing full takeover. The impact spans confidentiality, integrity, and availability, with a CVSS base score of 9.8.

Affected Systems

Oracle Corporation’s Agile PLM product, version 9.3.6, is the only impacted release identified in the advisory.

Risk and Exploitability

The CVSS score of 9.8 indicates that exploitation would give an attacker almost complete control over the system. The vulnerability is easily exploitable, requiring only an unauthenticated network connection to the HTTP interface. An EPSS score of < 1% is reported, indicating that the probability of exploitation is very low but nonzero, yet the severity warrants immediate attention. The vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 20, 2026 at 19:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle-released patch for Agile PLM 9.3.6 as soon as it becomes available.
  • Configure firewall or network access controls to limit HTTP traffic to trusted IP addresses only, thereby reducing exposure.
  • Monitor Agile PLM logs for anomalous authentication or configuration changes and enable additional logging to detect potential exploitation attempts.

Generated by OpenCVE AI on August 20, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Takeover of Oracle Agile PLM 9.3.6

Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Takeover of Oracle Agile PLM 9.3.6

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Agile PLM 9.3.6

Wed, 19 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Agile PLM 9.3.6
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:05:42.752Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71040

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:03.763

Modified: 2026-08-25T16:27:24.140

Link: CVE-2026-71040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:45:03Z

Weaknesses