Junglewise Threat Intelligence

CVE-2026-71040: Oracle Agile PLM authentication bypass in Security component

CVE-2026-71040 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Oracle Agile Product Lifecycle Management, Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a product lifecycle management system used by enterprises to manage products, components, and supply chain workflows. An unauthenticated attacker can exploit a security flaw via network-accessible HTTP to gain complete control of the system, potentially exposing sensitive product data, design information, and supply chain intelligence while disrupting business operations.

Technical details

The vulnerability is an easily exploitable authentication bypass in the Security component of Oracle Agile PLM version 9.3.6. It allows unauthenticated attackers with network access to reach the affected component via HTTP without requiring prior authentication or user interaction. A successful exploit results in complete system compromise with high impact to confidentiality, integrity, and availability. The CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects the critical nature of an unauthenticated, remotely exploitable flaw with maximum impact. Patch availability has not been confirmed in the advisory.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-08-18: disclosed

References

Related threats