Junglewise Threat Intelligence

CVE-2026-61167: Oracle Agile PLM security bypass in Security component

CVE-2026-61167 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a critical security vulnerability in its security component. An unauthorized attacker can exploit this flaw over the network without any user interaction or valid credentials. A successful attack could lead to a complete takeover of the system, potentially exposing sensitive product designs, intellectual property, and supply chain operations.

Technical details

A critical vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw is categorized as easily exploitable, requiring no authentication or user interaction (PR:N/UI:N). An attacker can exploit this vulnerability remotely over the network via HTTP. Successful exploitation grants the attacker full control over the Agile PLM instance, impacting confidentiality, integrity, and availability. The vulnerability was addressed in the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats