Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-08-18
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Agile PLM MCAD Connector product (CAX Client component) has a weakness that allows an attacker who already has high‑privilege access to the infrastructure where the connector runs to perform unauthorized updates, inserts or deletes on data that the connector exposes. The vulnerability is an improper access control flaw, which can lead to a compromise of the integrity of records managed by the connector. No confidentiality or availability impacts are reported.

Affected Systems

Affected vendors include Oracle Corporation. The product is Oracle Agile PLM MCAD Connector, version 3.6. No other versions are mentioned in the official advisories.

Risk and Exploitability

The CVSS 3.1 base score is 1.9, indicating a low severity integrity impact. The exploit requires a local attacker with high‑privilege user credentials on the host machine; the vector is inferred to be local network access or direct system login, as the description states an attacker with logon to the infrastructure can exploit it. The EPSS score indicates a probability of exploitation less than 1%, and the vulnerability has not been added to CISA’s KEV catalog. Because the attack requires existing privileged access, the overall risk to isolated or well‑segmented environments is limited, but it remains an integrity risk for any environment where users have elevated local rights or where the connector is deployed on a compromised host.

Generated by OpenCVE AI on August 20, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available patch or upgrade Oracle Agile PLM MCAD Connector to a version that does not contain the flaw.
  • Restrict local login access to the host running the connector, ensuring only trusted administrators can log on.
  • Enforce role‑based access controls within the connector, limiting update, insert, and delete permissions to users with explicit authorization.
  • Enable auditing of data modification operations in the connector and regularly review logs for suspicious activity.

Generated by OpenCVE AI on August 20, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Attacker Can Modify Oracle Agile PLM MCAD Connector Data

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Attacker Can Modify Oracle Agile PLM MCAD Connector Data

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Integrity Compromise via Unauthorized Data Modification in Oracle Agile PLM MCAD Connector

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Integrity Compromise via Unauthorized Data Modification in Oracle Agile PLM MCAD Connector
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:02:44.393Z

Reserved: 2026-08-04T22:06:34.616Z

Link: CVE-2026-71081

cve-icon Vulnrichment

Updated: 2026-08-19T15:01:00.647Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:08.290

Modified: 2026-08-24T16:15:56.627

Link: CVE-2026-71081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:00:07Z

Weaknesses