Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The weakness in the CAX Client component of Oracle Agile PLM MCAD Connector 3.6 allows an attacker with local access to read restricted data. The vulnerability is a classic sensitive information exposure that results in confidentiality impact when the attacker logs onto the infrastructure where the Connector is running. Successful exploitation does not affect integrity or availability, but it permits the attacker to survey a subset of data readable through the Connector.

Affected Systems

Oracle Corporation’s Oracle Agile PLM MCAD Connector, version 3.6. No other versions are reported as affected. The product is part of Oracle Supply Chain and the specific component impacted is the CAX Client. Administrators should confirm that any deployment of Connector 3.6 is identified as vulnerable.

Risk and Exploitability

The CVSS vector indicates a local attack with low privilege and no user interaction. The base score of 2.5 reflects a low risk to confidentiality only. Because the EPSS score is <1% and the vulnerability is not in CISA’s KEV catalogue, there is no evidence of active exploitation. The attack requires that the attacker already has logon rights on the host where the Connector runs, making it a local privilege issue rather than a remote surface. With this limited scope, the overall threat is low, but any exposure of sensitive data can still be significant to the organization’s trust and regulatory posture.

Generated by OpenCVE AI on August 20, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the installed version of Oracle Agile PLM MCAD Connector and determine if an official patch or update is available from Oracle; apply it promptly if it addresses this vulnerability.
  • If no patch is available, reduce the local privilege level required to access the Connector by tightening file system and application permissions; ensure that only trusted users or services can run the Connector processes.
  • Implement network segmentation or containerization to isolate the Connector from other services so that even if an attacker gains local access, the attack surface is limited.
  • Consider enabling audit logging for read operations on the Connector to detect and respond to unauthorized data access attempts in real time.

Generated by OpenCVE AI on August 20, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Agile Plm Mcad Connector
Vendors & Products Oracle Corporation
Oracle Corporation oracle Agile Plm Mcad Connector

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Sensitive Information Exposure in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Sensitive Information Exposure in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
Oracle Corporation Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:02:36.761Z

Reserved: 2026-08-04T22:06:34.616Z

Link: CVE-2026-71082

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:08.407

Modified: 2026-08-24T16:16:23.797

Link: CVE-2026-71082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:32:01Z

Weaknesses