Executive brief
Oracle Agile PLM is a product lifecycle management system used to manage product design, engineering, and supply chain data. A vulnerability in the Excel Plugin component allows low-privileged users with network access to modify or delete critical product data and crash the system, disrupting operations and potentially compromising data integrity.
Technical details
This vulnerability in Oracle Agile PLM's PGC/Excel Plugin is an integrity and availability flaw that can be exploited by low-privileged users over the network via HTTP. No user interaction is required; the attacker needs only network access and valid low-level credentials. Successful exploitation allows unauthorized creation, deletion, or modification of critical data accessible within Oracle Agile PLM, as well as the ability to trigger denial-of-service conditions through repeated crashes or hangs. The affected version is 9.3.6; patches or mitigations should be available from Oracle.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-08-18: disclosed