Junglewise Threat Intelligence

CVE-2026-61170: Oracle Agile PLM security bypass in Security component

CVE-2026-61170 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a security vulnerability in its core security component. An unauthorized attacker could exploit this flaw over the network to gain full control of the application. A successful compromise would allow the attacker to access sensitive product data, disrupt operations, and compromise the integrity of the supply chain management system.

Technical details

A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw allows an unauthenticated attacker to achieve a full compromise (Confidentiality, Integrity, and Availability) of the system via the HTTP protocol. While the attack vector is network-based and requires no user interaction or privileges, Oracle classifies the exploit complexity as 'High,' suggesting specific environmental conditions or timing may be required for a successful attack. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats