Executive brief
Oracle Agile PLM is a supply chain product used to manage product design, lifecycle, and collaboration workflows. A flaw in the Folders, Files & Attachments component allows a low-privileged attacker to gain unauthorized access to sensitive product data or modify records by tricking a legitimate user into performing an action. The attack compromises the confidentiality and integrity of all PLM-managed data, potentially affecting dependent business systems.
Technical details
The vulnerability is an authorization or cross-site request forgery (CSRF) class flaw in the Folders, Files & Attachments component of Oracle Agile PLM. It requires low privilege authentication and network access via HTTP, plus user interaction (social engineering or phishing) to trigger. An attacker can achieve unauthorized read and limited write access to PLM data with a scope change indicating impact beyond the vulnerable component itself. Patch status is unknown from the available advisory text; Oracle typically publishes fixes in critical patch updates.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-09-15: disclosed