Executive brief
A security vulnerability has been identified in Oracle Agile PLM, a software suite used by companies to manage product lifecycles and supply chain data. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive business information. This could lead to the exposure of critical proprietary data or complete access to all data stored within the system.
Technical details
A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation results in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data, representing a high confidentiality impact. The vulnerability does not require user interaction or elevated privileges. Organizations are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.