Executive brief
Oracle Agile PLM is a product lifecycle management suite used by enterprises to manage product data and supply chain operations. A flaw in the Security component allows a low-privileged user with local access to take full control of the system and potentially affect other connected systems. Successful exploitation grants complete administrative privileges, leading to data theft, system compromise, and operational disruption.
Technical details
This vulnerability in Oracle Agile PLM's Security component is an easily exploitable privilege escalation flaw requiring low-privilege local access (logon to the infrastructure where the product executes). The attack vector is local with low complexity, and no user interaction is required. Successful exploitation allows an attacker to fully compromise the Agile PLM instance with confidentiality, integrity, and availability impacts. The scope is changed, meaning attacks may impact additional products beyond Agile PLM itself. Patches are expected from Oracle; refer to the official Oracle security advisory for fix availability and mitigation guidance.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-08-18: disclosed