Sceawere

Vulnerability Detail

CVE-2026-61171Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM Security Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:48.817Z",
  "pubdate": "2026-07-21T22:18:48.817Z",
  "executiveSummary": "This vulnerability affects Oracle Agile PLM version 9.3.6 and resides within the product's Security component.\nThe flaw is categorized as an unauthenticated access vulnerability, allowing remote attackers to compromise the system over HTTP.\nSuccessful exploitation permits unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive information stored within the application.\nThe vulnerability carries a CVSS 3.1 Base Score of 9.1, reflecting a high severity due to significant impacts on both data confidentiality and integrity.\nThe exploitation process does not require user interaction or pre-existing privileges, meaning an attacker with network access can fully compromise the data integrity and confidentiality of the target PLM environment.\nOrganizations using the affected version are at high risk of unauthorized data manipulation and information disclosure.",
  "technicalDetails": "The vulnerability manifests within the Security component of Oracle Agile PLM 9.3.6, resulting in a critical failure of the authentication or authorization mechanism. The vulnerability enables an unauthenticated attacker to interact with the application via standard HTTP requests, effectively bypassing intended security controls that protect critical business data.\nThe exploitation flow begins with the attacker initiating unauthorized HTTP requests targeted at the application's API or web interface endpoints. Because the security component fails to properly validate the identity of the requester or the authorization state of the request, the system treats the malicious traffic as legitimate. This lack of verification allows the attacker to execute unauthorized commands or queries.\nBy manipulating the request parameters or the URI, an attacker can perform arbitrary CRUD (Create, Read, Update, Delete) operations on the database and associated file storage systems managed by the Oracle Agile PLM platform. The scope of the attack allows for the modification or deletion of intellectual property, product configuration data, and other sensitive supply chain artifacts. Furthermore, an attacker can exfiltrate sensitive data, leading to a complete breach of confidentiality regarding the product lifecycle management environment.\nThe attack vector is identified as network-based (AV:N), meaning the vulnerability is remotely exploitable without physical access to the server. The low attack complexity (AC:L) indicates that the flaw does not require specialized conditions for success. Crucially, the vulnerability does not require authentication (PR:N) nor does it require any form of user interaction (UI:N). The scope (S:U) remains unchanged, meaning the impact is localized to the Oracle Agile PLM application itself, although the potential for complete data compromise within that environment remains critical.\nThe root cause points to improper access control logic within the Security component that governs HTTP entry points. The absence of robust session or identity token verification allows for complete administrative or system-level data access by unauthorized actors. Post-exploitation, the impact involves total loss of integrity and confidentiality for all PLM-managed data, effectively undermining the security posture of the entire supply chain management system.\nThe exploitation behavior involves the injection of crafted HTTP payloads to bypass standard authorization checks. Once the initial entry point is bypassed, the attacker can move laterally through the application's data management features, altering, extracting, or destroying critical system information without ever needing valid credentials."
}
CVE-2026-61171: Oracle Agile PLM Security Bypass (CRITICAL Severity, CVSS: 9.1) - Sceawere