Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the CAX Client component of Oracle’s Agile PLM MCAD Connector. An unauthenticated attacker who has physical access to the device’s communication segment can exploit the flaw, enabling them to insert, update, or delete data and to read protected data. The primary impact is that confidentiality and integrity of the protected data can be compromised because sensitive configuration or business information may be altered or exposed.

Affected Systems

Oracle Corporation’s Agile PLM MCAD Connector version 3.6 is the only affected release listed. No other versions or components are known to be vulnerable at this time.

Risk and Exploitability

The CVSS base score of 3.7 indicates low overall impact, and the EPSS score of less than 1 percent reflects a very low likelihood of exploitation. The attack requires physical proximity and human interaction, so restricting access to the hardware significantly mitigates risk, but the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 20, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for version 3.6 or upgrade to a non‑vulnerable release.
  • Restrict physical access to the hardware communication segment to authorized personnel only and enforce strict access controls.
  • Monitor system and audit logs for unauthorized insert, update, delete, or read operations on protected data.

Generated by OpenCVE AI on August 20, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Unauthorized Data Modification in Oracle Agile PLM MCAD Connector

Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Unauthorized Data Modification in Oracle Agile PLM MCAD Connector

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Physical Access to Agile PLM MCAD Connector

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Physical Access to Agile PLM MCAD Connector
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:02:54.139Z

Reserved: 2026-08-04T22:06:34.616Z

Link: CVE-2026-71080

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:08.177

Modified: 2026-08-24T16:15:51.363

Link: CVE-2026-71080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:00:07Z

Weaknesses