Executive brief
Oracle Agile PLM MCAD Connector is a component used in supply chain product lifecycle management to integrate CAD systems. A low-privileged attacker with local system access can exploit this vulnerability to modify, create, or delete critical supply chain data and read sensitive product information, potentially disrupting manufacturing processes and exposing confidential design data.
Technical details
This is a local privilege escalation vulnerability in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6. The vulnerability is easily exploitable by a low-privileged local attacker with logon access to the infrastructure running the connector. Successful exploitation allows unauthorized read, creation, deletion, and modification of data accessible to the connector, with scope change indicating potential impact on additional Oracle systems. The CVSS 3.1 score of 7.3 reflects local attack vector, low privilege requirement, no user interaction, and high integrity impact combined with limited confidentiality impact. Oracle has assigned CVE-2026-83277; patch status and detailed technical remediation guidance should be obtained from Oracle's security advisory.
Affected products
- Oracle Agile PLM MCAD Connector 3.6
Timeline
- 2026-09-15: disclosed