Junglewise Threat Intelligence

CVE-2026-61166: Oracle Agile PLM account takeover in User and User Group component

CVE-2026-61166 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a high-severity vulnerability in its User and User Group component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive intellectual property, disruption of manufacturing processes, and unauthorized modification of product data.

Technical details

A vulnerability in the User and User Group component of Oracle Agile PLM version 9.3.6 allows for a complete application takeover. The flaw is categorized as easily exploitable and requires only low-privileged (PR:L) authentication to execute. An attacker can reach the vulnerable component via HTTP over the network (AV:N) without any interaction from a legitimate user (UI:N). Successful exploitation results in a total compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published in Oracle Critical Patch Update

References

Related threats