Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover via HTTP
Action: Apply Patch
AI Analysis

Impact

A flaw in Oracle Agile PLM’s Folders, Files & Attachments component allows a low‑privileged attacker with network access over HTTP to compromise the entire application. Successful exploitation can result in full control of the PLM system, compromising confidentiality, integrity, and availability of all managed data.

Affected Systems

Oracle Agile PLM 9.3.6 is affected. This version of the product, part of Oracle Supply Chain, is the only one listed with the issue; newer releases have not been reported as impacted.

Risk and Exploitability

The CVSS v3.1 Base Score of 7.5 reflects a high impact to all security properties, while the attack vector of network access and the low privilege requirement suggest that an attacker does not need advanced expertise, only connectivity. The EPSS score of less than 1% indicates that active exploitation has been low, and the vulnerability is not listed in the CISA KEV catalog. Likely, the attack path involves sending crafted HTTP requests to the vulnerable component from a compromised or malicious host, bypassing normal authorization checks and leading to takeover.

Generated by OpenCVE AI on September 20, 2026 at 06:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle Agile PLM patch or upgrade to a version that includes the fix
  • Restrict network access to the PLM HTTP interface to trusted hosts or apply IP filtering
  • Enforce strict role‑based access controls and least privilege on folders, files and attachments
  • Monitor access logs for anomalous activity and investigate any unauthorized requests

Generated by OpenCVE AI on September 20, 2026 at 06:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Attack Enables Oracle Agile PLM Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Agile PLM Low‑Privilege Files & Attachments
Weaknesses CWE-285

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Oracle Agile PLM Low‑Privilege Files & Attachments
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:12:20.958Z

Reserved: 2026-09-08T21:49:12.407Z

Link: CVE-2026-87254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:14.160

Modified: 2026-09-23T17:53:09.750

Link: CVE-2026-87254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses