Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Security component of Oracle Agile PLM version 9.3.6 allows a local, low‑privileged attacker who can log into the host to compromise the application. The flaw enables the attacker to take full control of the Agile PLM system, allowing unauthorized disclosure of confidential data, modification of business processes, and denial of service to users. The impact is total loss of confidentiality, integrity, and availability for the application.

Affected Systems

Oracle Agile PLM version 9.3.6 from Oracle Corporation. No other versions are listed as affected, though the description notes that successful exploitation could affect additional products integrated with Agile PLM due to the scope change.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild, yet the description states the exploit is easily achievable by a local user with low privileges. It is not listed in the CISA KEV catalog. The attack vector is local and requires an existing login, relying on the attacker’s ability to reach the host where Agile PLM runs.

Generated by OpenCVE AI on August 20, 2026 at 23:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to the secured version of Oracle Agile PLM as detailed in Oracle’s August 2026 security advisory.
  • Enforce strict local access controls and least privilege on the infrastructure hosting Agile PLM, ensuring only authorized users can log in.
  • If a patch is not immediately available, isolate the vulnerable system from the network and monitor for suspicious local activity.

Generated by OpenCVE AI on August 20, 2026 at 23:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Thu, 20 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Oracle Agile PLM Compromise and Takeover

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full Takeover of Oracle Agile PLM 9.3.6

Wed, 19 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Full Takeover of Oracle Agile PLM 9.3.6
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:04:54.953Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:04.483

Modified: 2026-08-25T16:27:10.390

Link: CVE-2026-71046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:15:05Z

Weaknesses