Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Agile PLM MCAD Connector version 3.6 allows an attacker who can access the hardware’s physical communication segment to gain low‑privilege access to the connector. The vulnerability enables the attacker to read, insert, update or delete data exposed by the connector, thereby compromising the confidentiality and integrity of the system’s data while not affecting availability. The weakness originates from insufficient authorization controls within the CAX Client component, as the attacker can perform privileged operations without proper checks.

Affected Systems

The affected product is Oracle Agile PLM MCAD Connector from Oracle Corporation, specifically version 3.6.

Risk and Exploitability

The calculated CVSS score is 4.6, indicating moderate severity with low confidentiality and integrity impacts. Exploitation requires physical access to the communication interface, and the attacker must already have low‑level privileges on the connected hardware. The EPSS score is less than 1 percent and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower exploitation probability at the time of analysis. However, because the attack vector is local and physical, the risk remains significant for environments where such access is possible or inadequately protected.

Generated by OpenCVE AI on August 19, 2026 at 14:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Oracle Agile PLM MCAD Connector update that mitigates this vulnerability, as detailed in Oracle’s security alert.
  • Restrict physical access to the hardware and communication segment that the connector uses; ensure that only authorized personnel and systems can reach it.
  • Review and tighten the connector’s access control lists and authentication mechanisms to confirm that only authorized users can perform read, insert, update, or delete operations.

Generated by OpenCVE AI on August 19, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Physical Access in Oracle Agile PLM MCAD Connector
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T18:32:56.696Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71071

cve-icon Vulnrichment

Updated: 2026-08-24T18:32:50.052Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:07.153

Modified: 2026-08-25T16:35:06.083

Link: CVE-2026-71071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses