Junglewise Threat Intelligence

CVE-2026-87256: Oracle Agile PLM authorization bypass in Application Server

CVE-2026-87256 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Agile Product Lifecycle Management, Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a product lifecycle management system used by enterprises to manage product data and supply chain operations. A vulnerability in its Application Server allows low-privileged attackers with network access to gain unauthorized access to sensitive product and manufacturing data, potentially affecting downstream systems and operations that depend on this data.

Technical details

An authorization or access control vulnerability exists in the Oracle Agile PLM Application Server (version 9.3.6) that allows network-accessible exploitation via HTTP. The vulnerability requires low-privilege credentials and no user interaction, enabling attackers to bypass authentication or authorization controls and access confidential data. Successful exploitation grants complete read access to Oracle Agile PLM's data repository, and the scope change indicates the vulnerability may have a ripple effect on dependent systems. A patch should be available from Oracle's October 2026 Critical Patch Update.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-09-15: disclosed

References

Related threats