Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to sensitive data
Action: Apply Patch
AI Analysis

Impact

The flaw exists in the Application Server component of Oracle Agile PLM 9.3.6 and allows a low‑privileged attacker who can reach the system over HTTP to bypass authentication or authorization checks, gaining unauthorized read access to all data the application exposes. This results in a confidentiality breach but does not alter data integrity or availability.

Affected Systems

Oracle Agile PLM version 9.3.6 is the only explicitly vulnerable release. The CNA notes that the flaw’s impact scope can extend to additional Oracle supply‑chain products that rely on the same instance, potentially exposing a wider set of data if the same vulnerability is present.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 marks the issue as high severity, yet the EPSS score of less than 1 % indicates exploitation attempts are rare so far and the flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability over the network using plain HTTP and need only low‐privileged access, which simplifies the attack vector, but the confidentiality impact remains significant.

Generated by OpenCVE AI on September 18, 2026 at 16:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle‑published patch for Agile PLM 9.3.6 or upgrade to a newer release that eliminates the flaw.
  • Restrict access to the Agile PLM HTTP endpoint to approved IP addresses or networks using firewall or reverse‑proxy rules.
  • Monitor authentication logs for anomalous activity and investigate any unexpected read access attempts promptly.

Generated by OpenCVE AI on September 18, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Agile PLM 9.3.6 Unauthorized Access via HTTP

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Oracle Agile PLM 9.3.6 Unauthorized Access via HTTP
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Plm
CPEs cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Plm
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Plm Agile Product Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:12:11.665Z

Reserved: 2026-09-08T21:49:12.407Z

Link: CVE-2026-87256

cve-icon Vulnrichment

Updated: 2026-09-17T14:22:17.041Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:14.270

Modified: 2026-09-23T17:52:56.723

Link: CVE-2026-87256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:00:13Z

Weaknesses