Junglewise Threat Intelligence

CVE-2026-83260: Oracle Agile PLM remote code execution in Event Java PX

CVE-2026-83260 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a supply chain product management system used to manage complex manufacturing processes and product data across enterprise environments. A remote code execution vulnerability in the Event Java PX component allows attackers with high privileges and network access to fully compromise the system and potentially impact connected supply chain applications, resulting in complete loss of confidentiality, integrity, and availability of critical product lifecycle management data.

Technical details

The vulnerability exists in the Event Java PX component of Oracle Agile PLM 9.3.6 and is exploitable via T3 and IIOP network protocols. The flaw allows high-privileged attackers with network-level access to execute arbitrary code and achieve complete system takeover. While the vulnerability is localized to Agile PLM, successful exploitation can impact the confidentiality, integrity, and availability of connected supply chain systems due to scope change. The attack requires existing high privileges but does not require user interaction.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-09-15: disclosed

References

Related threats