Sceawere

Vulnerability Detail

CVE-2026-71042UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM PGC Flaw

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:18:03.990Z",
  "pubdate": "2026-08-18T21:18:03.990Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Oracle Agile PLM product of Oracle Supply Chain, specifically residing in the PGC / Excel Plugin component.\nThe vulnerability affects supported version 9.3.6 and allows a low-privileged attacker with network access via HTTP to compromise the application.\nSuccessful exploitation of this flaw results in severe integrity and availability impacts, granting the attacker unauthorized capabilities to create, delete, or modify critical data or all data accessible by Oracle Agile PLM.\nAdditionally, successful attacks can cause a system hang or a frequently repeatable crash, resulting in a complete denial of service (DoS) condition.\nThe CVSS 3.1 base score is 8.1, reflecting high impacts to data integrity and system availability without affecting confidentiality.\nThe CVSS vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), indicating network attack vector, low attack complexity, low privilege requirements, and no user interaction required.",
  "technicalDetails": "The vulnerability affects the PGC / Excel Plugin component of Oracle Agile PLM version 9.3.6.\nThe attack vector is network-based (AV:N), meaning the vulnerable service is exposed over the network and accessible via the HTTP protocol.\nThe attack complexity is rated as low (AC:L), indicating that the attacker does not require specialized conditions or complex pre-requisites to successfully execute the exploit against the target.\nThe exploitation process requires low privileges (PR:L), meaning the attacker must authenticate to the application with a low-privileged user account before launching the attack payload.\nNo user interaction is required (UI:N), allowing the attack to be executed programmatically and directly against the target component.\nThe scope is unchanged (S:U), meaning the vulnerability impacts only the immediate authorization and execution domain of the Oracle Agile PLM application.\nDuring the attack flow, the adversary leverages network access via HTTP to interact with the PGC / Excel Plugin component, submitting malicious payloads designed to bypass access controls or exhaust system resources.\nPost-exploitation impacts include unauthorized creation, deletion, or modification of critical enterprise data and all accessible Oracle Agile PLM records, leading to a severe breach of data integrity.\nFurthermore, the payload behavior induces resource exhaustion or unhandled application exceptions, precipitating a complete denial of service characterized by a system hang or frequently repeatable application crash."
}
CVE-2026-71042: Oracle Agile PLM PGC Flaw (HIGH Severity, CVSS: 8.1) - Sceawere