Sceawere

Vulnerability Detail

CVE-2026-61167Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM Remote Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:48.367Z",
  "pubdate": "2026-07-21T22:18:48.367Z",
  "executiveSummary": "A critical security vulnerability exists in the Oracle Agile PLM product within the Oracle Supply Chain suite, specifically affecting version 9.3.6. Classified with a CVSS 3.1 base score of 9.8, this flaw represents a severe risk to organizational infrastructure.\nThe vulnerability resides in the product's security component and allows an unauthenticated remote attacker to achieve a full system compromise. Exploitation requires only network access via the HTTP protocol, with no user interaction or elevated privileges necessitated. The impact of successful exploitation is comprehensive, affecting the Confidentiality, Integrity, and Availability of the application, effectively granting the attacker full control over the Oracle Agile PLM environment. Given the ease of exploitation—characterized by low attack complexity—this vulnerability poses an immediate threat to the operational stability and data security of the affected PLM instances.",
  "technicalDetails": "The vulnerability is situated within the Security component of Oracle Agile PLM 9.3.6. It functions as a critical remote code execution or authentication bypass vulnerability that grants an unauthenticated attacker full administrative control over the application. The root cause pertains to an improper implementation of security controls that fails to validate or restrict inbound HTTP requests, allowing unauthorized entities to interact with backend management functions.\nExploitation is facilitated through the network layer via the HTTP protocol. Because the vulnerability does not require authentication (PR:N) and does not involve user interaction (UI:N), an attacker can interact directly with the vulnerable security component by crafting malicious HTTP requests. The low attack complexity (AC:L) suggests that the underlying defect in the code is easily discoverable and exploitable without the need for sophisticated bypass techniques.\nThe attack flow follows a direct trajectory: 1. Network Reconnaissance: The attacker identifies the Oracle Agile PLM instance exposed to the network. 2. Request Injection: The attacker sends specially crafted HTTP packets targeting the specific security module. 3. Security Bypass: The vulnerable component fails to enforce access control lists or authentication tokens, treating the unauthorized request as a legitimate command. 4. Code Execution: The backend environment processes the malicious input, leading to the execution of arbitrary commands or unauthorized administrative operations.\nThe post-exploitation impact is total system takeover. An attacker achieving this state can bypass all existing access controls, exfiltrate sensitive product lifecycle data, inject malicious artifacts, modify existing workflows, or effectively disable the service, resulting in a complete denial of availability. The lack of scope change (S:U) indicates that the impact is contained within the Oracle Agile PLM application environment, but within that boundary, the attacker gains full control over Confidentiality, Integrity, and Availability (C:H/I:H/A:H)."
}
CVE-2026-61167: Oracle Agile PLM Remote Takeover (CRITICAL Severity, CVSS: 9.8) - Sceawere