Junglewise Threat Intelligence

CVE-2026-71045: Oracle Agile PLM security component vulnerability

CVE-2026-71045 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Agile Product Lifecycle Management, Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a supply chain management and product lifecycle tool used by enterprises to manage product data and workflows. An unauthenticated attacker can exploit a security vulnerability via network access to achieve full compromise of the system, including data theft, modification, and system unavailability, though successful exploitation requires tricking a user into interacting with the attack.

Technical details

This is an easily exploitable vulnerability in the Oracle Agile PLM Security component affecting version 9.3.6. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. The attack requires human interaction (a user clicking a malicious link or accepting a request), but does not require elevated privileges. Successful exploitation can result in complete system compromise with high impact on confidentiality, integrity, and availability. The vendor has been notified and patches are expected.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-08-18: disclosed

References

Related threats