Executive brief
Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a critical security flaw. An unauthorized person can gain full control over the system over the internet without needing a username or password. This could lead to the theft of sensitive intellectual property, disruption of manufacturing processes, or total loss of system access.
Technical details
A vulnerability classified as improper authentication (CWE-287) exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the affected Oracle Agile PLM instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8, reflecting its low complexity and lack of required privileges or user interaction. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle via NVD and security alert.
- 2026-06-17: advisory