Executive brief
Oracle Agile PLM is a product lifecycle management system used by organizations to manage product design, engineering, and compliance data. An unauthenticated attacker can bypass security controls via network access to read all confidential data stored in the system, including product specifications, intellectual property, and other sensitive business information without authorization.
Technical details
This is an authentication bypass vulnerability in the Security component of Oracle Agile PLM affecting version 9.3.6. The vulnerability is easily exploitable and requires no user interaction—an unauthenticated attacker with network access can send specially crafted HTTP requests to compromise the system. The attack vector is network-based (HTTP) with low complexity and no privileges or user interaction required. Successful exploitation grants unauthorized access to all data accessible through Oracle Agile PLM, resulting in high confidentiality impact. Oracle has released security updates to address this vulnerability.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-08-18: disclosed