Junglewise Threat Intelligence

CVE-2026-47009: Oracle Agile PLM unauthorized data access in Folders, Files & Attachments

CVE-2026-47009 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Agile PLM. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Agile PLM, a software suite used by businesses to manage product lifecycles and supply chain data. An attacker could trick a legitimate user into performing an action that allows the attacker to gain unauthorized access to sensitive corporate data. This could result in the exposure of critical intellectual property or complete access to all data stored within the system.

Technical details

A vulnerability in the 'Folders, Files & Attachments' component of Oracle Agile PLM version 9.3.6 allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires human interaction from a person other than the attacker (User Interaction: Required), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side attack vector. A successful exploit can lead to unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data, impacting confidentiality. The vulnerability is tracked as CVE-2026-47009 and was disclosed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats