Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6 and is an improper access control flaw. A low‑privileged attacker with logon to the host where the connector runs can read any data the connector stores, potentially exposing critical confidential information while leaving integrity and availability intact. The CVSS 3.1 score of 5.5 underscores a medium severity impact focused on confidentiality.

Affected Systems

Oracle Agile PLM MCAD Connector version 3.6, part of Oracle Supply Chain, is affected. Users running this connector on any infrastructure where the CAX Client component executes and where local logon privileges are granted can be impacted. All installations of this product that have not been patched or upgraded remain vulnerable.

Risk and Exploitability

The CVSS base score of 5.5 indicates a medium risk level. The EPSS score of less than 1 % implies that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a local, low‑privileged logged‑on session on the system hosting the connector, making the threat surface limited to environments with insufficiently restricted local accounts. If an attacker gains that access, they can read confidential data but cannot modify data or disrupt service.

Generated by OpenCVE AI on September 21, 2026 at 23:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the security patch or upgrade Oracle Agile PLM MCAD Connector as described in the Oracle security advisory at https://www.oracle.com/security-alerts/cspusep2026.html.
  • Restrict local user privileges on the host that runs the connector, ensuring only accounts required for application operation can log on locally and disabling unnecessary local accounts to enforce least‑privilege.
  • Monitor system and connector logs for suspicious local logins or read patterns, and configure alerts to detect unauthorized activity promptly.

Generated by OpenCVE AI on September 21, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Data Exposure in Oracle Agile PLM MCAD Connector

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Agile PLM MCAD Connector
Weaknesses CWE-284
CWE-287

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Agile PLM MCAD Connector
Weaknesses CWE-284
CWE-287

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Attacker Can Compromise Oracle Agile PLM MCAD Connector
Weaknesses CWE-284
CWE-287

Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Attacker Can Compromise Oracle Agile PLM MCAD Connector
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm Mcad Connector
CPEs cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm Mcad Connector
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Plm Mcad Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:05:33.332Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83274

cve-icon Vulnrichment

Updated: 2026-09-21T19:05:29.854Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:39.887

Modified: 2026-09-21T20:17:33.680

Link: CVE-2026-83274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T23:45:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor