Executive brief
Oracle Agile PLM is a product lifecycle management system used by organizations to manage product data and supply chain operations. An unauthenticated attacker can exploit a vulnerability in the Application Server component to access sensitive product and business data without credentials, or partially disable the system, impacting operations and data confidentiality.
Technical details
This is an easily exploitable authentication bypass or authorization flaw in Oracle Agile PLM's Application Server component. The vulnerability is reachable over the network via HTTP and requires no authentication or user interaction. An unauthenticated attacker can read critical data stored in the system and cause partial denial of service. The vulnerability affects Agile PLM version 9.3.6. Oracle has issued a patch or mitigation guidance; refer to Oracle's security advisories for remediation details.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-09-15: disclosed