Sceawere
Vulnerability Detail
CVE-2026-71040UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM Remote Takeover Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-18T21:18:03.763Z",
"pubdate": "2026-08-18T21:18:03.763Z",
"executiveSummary": "This advisory details a critical vulnerability affecting the Oracle Agile PLM product of Oracle Supply Chain, specifically within the Security component.\nThe vulnerability allows an unauthenticated attacker with network access via HTTP to fully compromise the target system.\nSuccessful exploitation of this flaw results in a complete takeover of Oracle Agile PLM, granting the attacker high-level control with severe impacts on confidentiality, integrity, and availability.\nThe severity of this flaw is reflected by a CVSS 3.1 Base Score of 9.8 out of 10.0, indicating a maximum-severity risk profile.\nThe attack vector is network-based, requiring low attack complexity with no user interaction or prior authentication privileges necessary.\nThe affected supported version identified is 9.3.6.\nOrganizations utilizing the specified vulnerable version face significant risk exposure and must apply available vendor patches immediately to prevent unauthorized remote exploitation.",
"technicalDetails": "The vulnerability resides within the Security component of the Oracle Agile PLM product, specifically affecting version 9.3.6.\nThe flaw can be exploited remotely over the network using the HTTP protocol without requiring any user interaction.\nBecause the vulnerability requires no authentication and no privileges, an unauthenticated remote attacker can directly interact with the exposed vulnerable endpoints.\nThe attack flow begins with the adversary sending crafted HTTP requests targeting the Security component of the Oracle Agile PLM application.\nDue to insufficient security controls, input validation, or authentication enforcement within the vulnerable component, the application processes the malicious payload improperly.\nThis execution path allows the attacker to bypass security mechanisms entirely, leading to unauthorized access and control over the underlying application logic.\nPost-exploitation impact includes a complete system takeover of Oracle Agile PLM, granting the adversary full administrative capabilities.\nThe impact encompasses complete compromise of confidentiality, allowing unauthorized access to sensitive proprietary supply chain data; integrity, enabling the modification or destruction of critical product lifecycle information; and availability, resulting in potential denial of service or operational disruption of the PLM environment.\nThe CVSS 3.1 vector associated with this vulnerability is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which mathematically codifies its remote exploitability, low complexity, absence of required privileges, and maximum impact across all three CIA triads."
}