Junglewise Threat Intelligence

CVE-2026-87257: Oracle Agile PLM unauthorized data access in SDK

CVE-2026-87257 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Agile Product Lifecycle Management, Oracle Agile PLM. Vendors: Oracle.

Executive brief

Oracle Agile PLM is a product lifecycle management system used by enterprises to manage product design, engineering, and supply chain data. An authentication bypass vulnerability in the SDK component allows a low-privilege, network-connected attacker to gain unauthorized access to sensitive product data and intellectual property stored in the system, potentially exposing critical business information across the entire supply chain organization.

Technical details

This is an authorization/authentication bypass vulnerability in the Oracle Agile PLM SDK component (version 9.3.6 and earlier). The vulnerability is easily exploitable over HTTP by a low-privileged attacker with network access, requiring no user interaction. The root cause involves improper access controls in the SDK that allow privilege escalation or authentication bypass. Successful exploitation grants attackers read access to all data managed by Oracle Agile PLM, including confidential product designs, engineering specifications, and supply chain information. The vulnerability has scope change, meaning compromises to Agile PLM may impact other connected systems in the Oracle ecosystem. Patches are expected from Oracle's security advisory, though the reference URL is currently unavailable.

Affected products

  • Oracle Agile PLM 9.3.6

Timeline

  • 2026-09-15: disclosed
  • other: CVE-2026-87257

References

Related threats