Executive brief
Oracle Agile PLM is a product lifecycle management system used by enterprises to manage product design and supply chain operations. A vulnerability in the Application Server component allows a low-privileged network attacker to gain complete control over the system, potentially compromising all stored product data, designs, and supply chain information.
Technical details
The vulnerability is a privilege escalation flaw in the Oracle Agile PLM Application Server that can be exploited by a low-privileged attacker with network access via HTTP. The attack requires no user interaction and does not require authentication bypass. A successful exploit allows the attacker to take over the entire Oracle Agile PLM system, resulting in complete compromise of confidentiality, integrity, and availability. Version 9.3.6 is confirmed affected. There is no indication the vulnerability is currently being exploited in the wild.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-08-18: disclosed