Junglewise Threat Intelligence

CVE-2026-61171: Oracle Agile PLM security bypass in Security component

CVE-2026-61171 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a critical security vulnerability. An unauthorized person can access the system over the internet without needing a username or password. This could allow an attacker to view, change, or delete sensitive corporate data, potentially disrupting operations and compromising intellectual property.

Technical details

A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data managed by the PLM system. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: NVD published date

References

Related threats