Executive brief
Oracle Agile PLM is a product lifecycle management system used to manage product designs and development workflows. A vulnerability in the Export component allows a low-privileged attacker with network access to completely compromise the system, potentially gaining full control over all data, configurations, and operations within the platform.
Technical details
This vulnerability in the Export component of Oracle Agile PLM is easily exploitable and requires only low privilege network access via HTTP. An authenticated attacker can achieve complete system compromise with high impact to confidentiality, integrity, and availability. The attack vector is network-based with low complexity and no user interaction required. Affected version is 9.3.6. Oracle has classified this as a high-severity issue with a CVSS 3.1 score of 8.8, indicating significant risk to production systems.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-08-18: disclosed