Junglewise Threat Intelligence

CVE-2026-71039: Oracle Agile PLM privilege escalation in Application Server

CVE-2026-71039 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Agile Product Lifecycle Management, Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a product lifecycle management system used by enterprises to manage product design and supply chain operations. A vulnerability in the Application Server component allows a low-privileged network attacker to gain complete control over the system, potentially compromising all stored product data, designs, and supply chain information.

Technical details

The vulnerability is a privilege escalation flaw in the Oracle Agile PLM Application Server that can be exploited by a low-privileged attacker with network access via HTTP. The attack requires no user interaction and does not require authentication bypass. A successful exploit allows the attacker to take over the entire Oracle Agile PLM system, resulting in complete compromise of confidentiality, integrity, and availability. Version 9.3.6 is confirmed affected. There is no indication the vulnerability is currently being exploited in the wild.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-08-18: disclosed

References

Related threats