Sceawere
Vulnerability Detail
CVE-2026-71041UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM Compromise Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-08-18T21:18:03.877Z",
"pubdate": "2026-08-18T21:18:03.877Z",
"executiveSummary": "A vulnerability has been identified within the Oracle Agile PLM product of Oracle Supply Chain, specifically residing in the Gantt Chart component affecting version 9.3.6. This security flaw is classified as difficult to exploit but presents severe risk implications, allowing a low-privileged authenticated attacker with local logon access to the underlying infrastructure where Oracle Agile PLM executes to achieve a complete system compromise. Successful exploitation of this vulnerability yields extensive impacts across confidentiality, integrity, and availability, effectively resulting in the full takeover of the Oracle Agile PLM application. The CVSS 3.1 base score is 7.0 with a vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The attack vector is strictly local (AV:L), requiring high attack complexity (AC:H), low privileges (PR:L), and no user interaction (UI:N). Defensive strategies must prioritize strict access controls on the host infrastructure, rigorous privilege management, and deployment of official vendor patches as supplied by Oracle to neutralize the underlying flaw within the Gantt Chart component.",
"technicalDetails": "The vulnerability resides within the Gantt Chart component of Oracle Agile PLM version 9.3.6, exposing the application to local compromise due to insufficient security controls or improper handling of execution contexts within the infrastructure. The root cause stems from weaknesses in how the Gantt Chart component processes internal routines, interacts with underlying system resources, or manages state when executed within the hosting environment. Exploitation of this vulnerability requires the threat actor to already possess low-privileged credentials and interactive or programmatic logon access to the specific infrastructure host executing the Oracle Agile PLM software. Because the attack vector is local (AV:L) and features high attack complexity (AC:H), the attacker must successfully orchestrate precise local conditions, manipulate local execution parameters, or leverage race conditions and misconfigurations present in the host environment to interact with the vulnerable Gantt Chart component. The step-by-step attack flow begins with the low-privileged user establishing a session on the target infrastructure. Subsequently, the attacker leverages their local privileges to target the execution space or inter-process communication mechanisms associated with the Oracle Agile PLM Gantt Chart component. By exploiting the high-complexity flaw, the attacker injects or manipulates input parameters, file handles, or execution flows processed by the component. Successful payload execution bypasses existing authorization boundaries within the application tier. Following post-exploitation, the attacker achieves complete control over the Oracle Agile PLM application instance. The resulting impact grants the adversary unauthorized read, write, and execute capabilities over sensitive product data, system configurations, and administrative functionalities, thereby compromising the confidentiality, integrity, and availability of the entire Oracle Agile PLM deployment."
}