Junglewise Threat Intelligence

CVE-2026-83274: Oracle Agile PLM MCAD Connector local privilege escalation in CAX Client

CVE-2026-83274 · Severity: medium · CVSS 5.5 · Published 2026-09-15

Technologies: Oracle Agile PLM MCAD Connector. Vendors: Oracle.

Executive brief

Oracle Agile PLM MCAD Connector is a product used to manage computer-aided design (CAD) data and integrate it with Oracle's product lifecycle management systems. A local vulnerability in the CAX Client component allows a low-privileged attacker with access to the infrastructure to bypass security controls and gain unauthorized access to sensitive project data and design files. This could lead to intellectual property theft, competitive disadvantage, or disruption of engineering workflows.

Technical details

The vulnerability is a local privilege escalation affecting the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6. The vulnerability allows a low-privileged user with logon access to the system to access confidential data without additional authentication or user interaction required. The attack vector is local (AV:L), and successful exploitation results in high-impact confidentiality breach—an attacker can read all data accessible by the Oracle Agile PLM MCAD Connector process. No information about patch availability is currently available from the advisory reference sources.

Affected products

  • Oracle Agile PLM MCAD Connector 3.6

Timeline

  • 2026-09-15: disclosed

References

Related threats