Executive brief
Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a security vulnerability. An attacker with basic user access to the corporate network can exploit this flaw to take full control of the system. This could lead to the theft of sensitive intellectual property, unauthorized changes to product designs, or a total disruption of supply chain operations.
Technical details
A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw is classified as easily exploitable and requires only low-privileged user credentials. An attacker can exploit this over the network via HTTP without requiring any user interaction. A successful exploit results in a complete compromise of the application, impacting confidentiality, integrity, and availability (CVSS 8.8). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD