Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Gantt Chart component of Oracle Agile PLM allows a low‑privileged user who can log onto the underlying infrastructure to compromise the entire application. Successful exploitation results in a full takeover of Oracle Agile PLM, compromising confidentiality, integrity, and availability as reflected in the CVSS 7.0 score. The vulnerability is considered difficult to exploit, but the impact is severe once activated.

Affected Systems

Oracle Corporation’s Agile PLM product, version 9.3.6, is the only version impacted. The attack vector involves the Gantt Chart module that processes user‑specifiable data within the application.

Risk and Exploitability

The CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates a moderate‑to‑high severity local exploit that requires only low privileged access. The EPSS score of 0.00109 indicates a very low probability of exploitation, yet the absence of an entry in the CISA KEV catalog suggests that no widespread exploitation has been reported yet. Nonetheless, the potential for complete system compromise warrants prompt attention.

Generated by OpenCVE AI on August 20, 2026 at 23:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a fixed release that addresses the Gantt Chart vulnerability once Oracle publishes it.
  • Enforce least‑privilege on all infrastructure accounts that have access to Oracle Agile PLM, limiting local system access to only those users who genuinely require it.
  • Monitor application and system logs for anomalous use of the Gantt Chart functionality and isolate the Agile PLM environment from other critical infrastructure components.

Generated by OpenCVE AI on August 20, 2026 at 23:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Thu, 20 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Oracle Agile PLM Gantt Chart Vulnerability Enables Local Privilege Escalation to Full System Takeover

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Local Exploit Enables Full Control of Oracle Agile PLM Gantt Chart

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Local Exploit Enables Full Control of Oracle Agile PLM Gantt Chart
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:05:36.569Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71041

cve-icon Vulnrichment

Updated: 2026-08-19T15:48:04.677Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:03.877

Modified: 2026-08-25T16:27:21.910

Link: CVE-2026-71041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:15:05Z

Weaknesses