Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker who has physical access to the communication segment connected to the hardware to compromise the Oracle Agile PLM MCAD Connector. By exploiting this weakness, the attacker can read critical data and perform unauthorized insert, update, or delete operations. According to the CVSS vector, the attack compromises confidentiality heavily (C:H) and integrity moderately (I:L).

Affected Systems

Oracle Agile PLM MCAD Connector version 3.6 is the only affected product listed in the advisory. This component is part of Oracle Supply Chain’s MCAD Connector and no other versions are indicated as impacted.

Risk and Exploitability

The CVSS Base Score of 5.9 indicates moderate severity. The attack requires local access (AV:A) with high complexity (AC:H) and no privileges (PR:N). The EPSS score of approximately 0.18% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the lack of a known remote exploitation vector further reduces the likelihood of widespread attacks. Nonetheless, the high confidentiality impact means that once the physical channel is compromised, sensitive data can be exfiltrated or altered.

Generated by OpenCVE AI on August 20, 2026 at 19:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle's security updates for version 3.6 and apply any available patch immediately.
  • Restrict physical access to the communication segment by implementing appropriate physical security measures or network segmentation to limit which devices can interface with the MCAD Connector.
  • Monitor system logs for unauthorized access attempts and set alerts on anomalous communication patterns.

Generated by OpenCVE AI on August 20, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Physical Access in Oracle Agile PLM MCAD Connector 3.6

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Physical Access in Oracle Agile PLM MCAD Connector 3.6

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Physical Access Unauthenticated Data Breach in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200
CWE-287

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Physical Access Unauthenticated Data Breach in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:03:26.928Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:07.613

Modified: 2026-08-24T16:16:34.887

Link: CVE-2026-71075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:15:04Z

Weaknesses