Junglewise Threat Intelligence

CVE-2026-71041: Oracle Agile PLM privilege escalation in Gantt Chart

CVE-2026-71041 · Severity: high · CVSS 7 · Published 2026-08-18

Technologies: Oracle Agile Product Lifecycle Management, Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a product lifecycle management tool used to manage manufacturing and supply chain processes. A vulnerability in its Gantt Chart component allows low-privileged local users with system access to gain complete control over the application, potentially exposing or modifying critical product and supply chain data. An attacker would need existing local access to the infrastructure where the application runs.

Technical details

This is a privilege escalation vulnerability in the Gantt Chart component of Oracle Agile PLM version 9.3.6. The vulnerability has a local attack vector (AV:L) and requires low privileges (PR:L) and local logon to the infrastructure, making it difficult to exploit remotely. Successful exploitation allows an attacker to completely compromise the application, achieving confidentiality, integrity, and availability impacts. The CVSS 3.1 vector (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates high complexity (AC:H) but high potential impact across all three security dimensions. No evidence of active exploitation in the wild is currently reported.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-08-18: disclosed

References

Related threats