Sceawere

Vulnerability Detail

CVE-2026-71041UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM Compromise Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM.
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-08-18T21:18:03.877Z",
  "pubdate": "2026-08-18T21:18:03.877Z",
  "executiveSummary": "A vulnerability has been identified within the Oracle Agile PLM product of Oracle Supply Chain, specifically residing in the Gantt Chart component affecting version 9.3.6. This security flaw is classified as difficult to exploit but presents severe risk implications, allowing a low-privileged authenticated attacker with local logon access to the underlying infrastructure where Oracle Agile PLM executes to achieve a complete system compromise. Successful exploitation of this vulnerability yields extensive impacts across confidentiality, integrity, and availability, effectively resulting in the full takeover of the Oracle Agile PLM application. The CVSS 3.1 base score is 7.0 with a vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The attack vector is strictly local (AV:L), requiring high attack complexity (AC:H), low privileges (PR:L), and no user interaction (UI:N). Defensive strategies must prioritize strict access controls on the host infrastructure, rigorous privilege management, and deployment of official vendor patches as supplied by Oracle to neutralize the underlying flaw within the Gantt Chart component.",
  "technicalDetails": "The vulnerability resides within the Gantt Chart component of Oracle Agile PLM version 9.3.6, exposing the application to local compromise due to insufficient security controls or improper handling of execution contexts within the infrastructure. The root cause stems from weaknesses in how the Gantt Chart component processes internal routines, interacts with underlying system resources, or manages state when executed within the hosting environment. Exploitation of this vulnerability requires the threat actor to already possess low-privileged credentials and interactive or programmatic logon access to the specific infrastructure host executing the Oracle Agile PLM software. Because the attack vector is local (AV:L) and features high attack complexity (AC:H), the attacker must successfully orchestrate precise local conditions, manipulate local execution parameters, or leverage race conditions and misconfigurations present in the host environment to interact with the vulnerable Gantt Chart component. The step-by-step attack flow begins with the low-privileged user establishing a session on the target infrastructure. Subsequently, the attacker leverages their local privileges to target the execution space or inter-process communication mechanisms associated with the Oracle Agile PLM Gantt Chart component. By exploiting the high-complexity flaw, the attacker injects or manipulates input parameters, file handles, or execution flows processed by the component. Successful payload execution bypasses existing authorization boundaries within the application tier. Following post-exploitation, the attacker achieves complete control over the Oracle Agile PLM application instance. The resulting impact grants the adversary unauthorized read, write, and execute capabilities over sensitive product data, system configurations, and administrative functionalities, thereby compromising the confidentiality, integrity, and availability of the entire Oracle Agile PLM deployment."
}
CVE-2026-71041: Oracle Agile PLM Compromise Vulnerability (HIGH Severity, CVSS: 7.0) - Sceawere