Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 4.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
Published: 2026-08-18
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability in Oracle Agile PLM MCAD Connector version 3.6 allows an attacker who has logged onto the host infrastructure to gain unauthorized update, insert or delete rights to the connector’s data, read protected data, or initiate a partial denial of service. The flaw requires that the attacker already have local access and that an additional human interaction from another user triggers the effect. The vulnerability is rated moderate, with a CVSS v3.1 base score of 4.5, and impacts confidentiality, integrity and availability for the affected component.

Affected Systems

Oracle Corporation’s Agile PLM MCAD Connector, version 3.6, is impacted. No other product versions or vendors are listed as affected.

Risk and Exploitability

The CVSS score of 4.5 and an EPSS of less than 1% indicate a modest likelihood of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Exploitation requires local host access and a non‑attacker’s human interaction, limiting the attack surface. Nonetheless, the potential for data integrity and availability loss warrants prompt attention and monitoring.

Generated by OpenCVE AI on August 19, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch or upgrade to a newer version of Oracle Agile PLM MCAD Connector if available.
  • Limit local logon accounts to the least privileges necessary for their role and enforce strict role‑based access controls.
  • Enable auditing and regularly review logs for unauthorized data modifications or signs of denial‑of‑service activity.

Generated by OpenCVE AI on August 19, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Access Can Modify Data and Cause Partial Denial of Service in Oracle Agile PLM MCAD Connector 3.6

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Access Can Modify Data and Cause Partial Denial of Service in Oracle Agile PLM MCAD Connector 3.6
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 4.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:08.398Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71066

cve-icon Vulnrichment

Updated: 2026-08-19T12:09:34.841Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:06.543

Modified: 2026-08-25T16:33:38.750

Link: CVE-2026-71066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T15:15:05Z

Weaknesses