Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-08-18
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6 permits an attacker with low‑privileged credentials on the host to compromise the connector. The vulnerability, identified as a CWE-284 Access Control weakness, can be exercised to interrupt or degrade the connector’s availability, resulting in a partial denial of service. The weakness solely affects availability and does not expose confidential or integrity data.

Affected Systems

Oracle Agile PLM MCAD Connector, version 3.6, distributed by Oracle Corporation.

Risk and Exploitability

The CVSS base score of 3.3 reflects a low severity impact focused on availability, while an EPSS score of less than 1% indicates a very low but nonzero likely exploitation chance. The vulnerability is not listed in the CISA KEV catalog, showing no current widespread exploitation. Attackers would need local access with limited privileges on the system where the connector runs, which is inferred from the description.

Generated by OpenCVE AI on August 20, 2026 at 19:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or upgraded version of Oracle Agile PLM MCAD Connector as released by Oracle in the security advisory.
  • Restrict local access to the server and limit user privileges so only trusted accounts can log on and run the connector.
  • Review Oracle's security advisories for the most recent patch or mitigation related to this vulnerability and ensure it is promptly applied.

Generated by OpenCVE AI on August 20, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Denial of Service in Oracle Agile PLM MCAD Connector

Thu, 20 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Denial of Service in Oracle Agile PLM MCAD Connector

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service Vulnerability in Oracle Agile PLM MCAD Connector via CAX Client
Weaknesses CWE-770

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service Vulnerability in Oracle Agile PLM MCAD Connector via CAX Client
Weaknesses CWE-770

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:08.238Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71072

cve-icon Vulnrichment

Updated: 2026-08-19T12:09:30.142Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:07.273

Modified: 2026-08-25T16:34:27.407

Link: CVE-2026-71072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:15:04Z

Weaknesses