Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and disclosure
Action: Patch/Isolate
AI Analysis

Impact

A flaw in Oracle Agile PLM 9.3.6 permits an attacker with physical access to the host’s communication segment to create, delete, or alter critical data without authentication. The vulnerability is an example of improper access control (CWE‑284) and represents an authorization bypass, resulting in loss of confidentiality and integrity of all data accessible through Oracle Agile PLM.

Affected Systems

Oracle Corporation’s Agile PLM, version 9.3.6. No other versions are listed as affected.

Risk and Exploitability

The CVSS 3.1 score of 6.8 indicates moderate severity with high confidentiality and integrity impact. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is physical access to the host’s communication segment, meaning remote exploitation over a network is not supported. The vulnerability requires only physical proximity; environments lacking a secured instrumentation network may see higher risk. The attacker can bypass authentication entirely, making it a serious threat for on‑premises deployments that are not isolated.

Generated by OpenCVE AI on September 20, 2026 at 05:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Limit physical access to the servers running Oracle Agile PLM
  • Isolate the application server from other network segments and use a dedicated VLAN or token‑based access
  • After a vendor fix becomes available, upgrade to the patched version or apply the official patch if one is released

Generated by OpenCVE AI on September 20, 2026 at 05:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Sun, 20 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Unauthorized Data Modification in Oracle Agile PLM

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Unauthorized Data Modification in Oracle Agile PLM
Weaknesses CWE-862

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Unauthorized Data Modification in Oracle Agile PLM
Weaknesses CWE-284
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:12:35.574Z

Reserved: 2026-09-08T21:49:12.406Z

Link: CVE-2026-87252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:13.940

Modified: 2026-09-23T17:53:57.083

Link: CVE-2026-87252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses