Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Agile PLM MCAD Connector version 3.6 includes a vulnerability in the CAX Client component that permits a high‑privilege attacker who has logged into the host system to read a subset of data exposed by the connector. The exploitation is considered difficult and requires interaction with a legitimate, non‑attacker user. The impact is an unauthorized disclosure of sensitive information, as reflected in the CVSS score of 1.8 with a low confidentiality impact.

Affected Systems

The vulnerability affects Oracle Agile PLM MCAD Connector version 3.6 (Oracle Supply Chain). It applies to installations of the CAX Client component that run on an infrastructure where Oracle Agile PLM MCAD Connector is deployed.

Risk and Exploitability

The CVSS score of 1.8 indicates low severity, with confidentiality impact limited to low. The EPSS score is <1%, showing a negligible probability of exploitation. Exploitation requires a high‑privileged user on the host machine and human interaction, making the attack difficult to execute. No evidence of active exploitation has been reported, and the issue is not listed in the CISA KEV catalog. Consequently, the immediate threat is low, but environments that rely on this connector should ensure that only trusted users have privileged access and monitor logs for any unauthorized read attempts.

Generated by OpenCVE AI on August 20, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Oracle Agile PLM MCAD Connector to a non‑vulnerable version following Oracle's security advisories
  • Restrict privileged access to the host environment where the connector runs to only trusted personnel
  • Implement monitoring of read operations on the connector data to detect potential unauthorized access

Generated by OpenCVE AI on August 20, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Limited Data Disclosure via Oracle Agile PLM MCAD Connector Vulnerability

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Limited Data Disclosure via Oracle Agile PLM MCAD Connector Vulnerability

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title High‑Privileged Data Read in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title High‑Privileged Data Read in Oracle Agile PLM MCAD Connector
Weaknesses CWE-200

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 1.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:02:29.590Z

Reserved: 2026-08-04T22:06:34.616Z

Link: CVE-2026-71083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:08.523

Modified: 2026-08-24T16:16:28.227

Link: CVE-2026-71083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:15:04Z

Weaknesses