Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in Oracle Agile PLM 9.3.6’s Web Client allows an unauthenticated attacker with HTTP network access to modify or read protected data. The flaw enables insertion, updating, or deletion of records and retrieval of information that should be inaccessible, creating confidentiality and integrity breaches. It stems from inadequate access control (CWE‑284).

Affected Systems

The only affected product is Oracle Agile PLM 9.3.6, specifically its Web Client component. No other versions or products are listed as impacted by this vulnerability.

Risk and Exploitability

The CVSS base score of 6.1 indicates low‑to‑medium severity with scope change, meaning compromised privilege can extend beyond the original scope. The EPSS value of less than 1% suggests that broad exploitation is unlikely at present, and the flaw is not in the CISA KEV catalog. Nonetheless, because the attack vector requires only an HTTP connection and the flaw permits unauthorized data modification and read, any instance exposed to a network, even through VPN or firewalls, remains at risk until a vendor fix is applied or the endpoint is tightly secured.

Generated by OpenCVE AI on September 20, 2026 at 06:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the official Oracle patch for Agile PLM 9.3.6 that corrects the Web Client access‑control issue.
  • If patching is delayed, segment the Agile PLM web service with a firewall and allow HTTP traffic exclusively from trusted internal networks or VPN endpoints.
  • Tighten role‑based permissions within Agile PLM so that only authorized users can perform update, insert or delete operations; routinely audit these permissions.
  • Enable comprehensive logging of data modification and unauthorized read events and monitor for suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 06:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Client Access Control Vulnerability in Oracle Agile PLM 9.3.6

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Update and Read in Oracle Agile PLM 9.3.6
Weaknesses CWE-269

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Update and Read in Oracle Agile PLM 9.3.6
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:12:29.473Z

Reserved: 2026-09-08T21:49:12.406Z

Link: CVE-2026-87253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:14.050

Modified: 2026-09-23T17:53:42.793

Link: CVE-2026-87253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses