Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is difficult to exploit and allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise the connector. A successful exploitation can result in unauthorized access to critical data or complete access to all data the connector can reach. The flaw represents an access control weakness (CWE‑284). The CVSS 3.1 score of 5.3 indicates a medium‑to‑high impact with a focus on confidentiality.

Affected Systems

Affected system is Oracle Agile PLM MCAD Connector from Oracle Corporation, version 3.6. The product requires a hardware module with a dedicated physical communication segment.

Risk and Exploitability

With a CVSS 3.1 base score of 5.3 and vectors AV:A, AC:H, PR:N, UI:N, S:U, C:H, the vulnerability poses a moderate risk when the connector is physically accessible. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Nonetheless, the requirement for physical or adjacent network access means that environments lacking strict physical security or network segmentation could be vulnerable to exploitation.

Generated by OpenCVE AI on August 20, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle Agile PLM MCAD Connector 3.6 when it becomes available.
  • Implement stringent authentication controls to enforce exclusive access to the connector services.
  • Block physical access to the connector’s communication segment by enforcing strict perimeter security and role‑based controls.
  • Segregate the connector’s communication segment from the rest of the network using VLANs or firewall rules to deny unauthorized adjacent traffic.
  • Enable and review audit logging for unauthorized access attempts to the connector.

Generated by OpenCVE AI on August 20, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via Physical Access in Oracle Agile PLM MCAD Connector

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via Physical Access in Oracle Agile PLM MCAD Connector

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Exploitation in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200
CWE-287

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Exploitation in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:03:10.546Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71077

cve-icon Vulnrichment

Updated: 2026-08-19T15:01:07.713Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:07.837

Modified: 2026-08-24T17:08:10.620

Link: CVE-2026-71077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:00:07Z

Weaknesses