Executive brief
Oracle Agile PLM is a product lifecycle management system used to manage product design, collaboration, and supply chain operations. A vulnerability in the Folders, Files & Attachments component allows a low-privileged authenticated user to gain full control of the system, compromising confidentiality, integrity, and availability of critical product data and operations.
Technical details
This is a difficult-to-exploit authentication/authorization bypass vulnerability in the Folders, Files & Attachments component of Oracle Agile PLM 9.3.6. The vulnerability requires network access via HTTP and a valid low-privileged user account, but no additional user interaction. An attacker with these preconditions can bypass access controls to gain full system compromise. The exact root cause and patching status are not publicly detailed in available sources, though Oracle has issued a security advisory addressing the issue.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-09-15: disclosed