Executive brief
Oracle Agile PLM MCAD Connector is a component used to integrate CAD tools with Oracle's supply chain management platform. A vulnerability in version 3.6 allows a low-privileged user with local access to the infrastructure to read sensitive product design and supply chain data without authorization, potentially exposing confidential engineering and manufacturing information.
Technical details
This is a local privilege escalation vulnerability in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6. The vulnerability requires local logon access to the infrastructure where the connector executes and does not require user interaction. Exploitation allows a low-privileged attacker to bypass access controls and gain read access to critical data stored within the Oracle Agile PLM MCAD Connector system. The vulnerability affects confidentiality but not integrity or availability. Patch status and fix details are not available in the provided advisory.
Affected products
- Oracle Agile PLM MCAD Connector 3.6
Timeline
- 2026-09-15: disclosed