Sceawere
Vulnerability Detail
CVE-2026-71042UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM PGC Flaw
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-18T21:18:03.990Z",
"pubdate": "2026-08-18T21:18:03.990Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Oracle Agile PLM product of Oracle Supply Chain, specifically residing in the PGC / Excel Plugin component.\nThe vulnerability affects supported version 9.3.6 and allows a low-privileged attacker with network access via HTTP to compromise the application.\nSuccessful exploitation of this flaw results in severe integrity and availability impacts, granting the attacker unauthorized capabilities to create, delete, or modify critical data or all data accessible by Oracle Agile PLM.\nAdditionally, successful attacks can cause a system hang or a frequently repeatable crash, resulting in a complete denial of service (DoS) condition.\nThe CVSS 3.1 base score is 8.1, reflecting high impacts to data integrity and system availability without affecting confidentiality.\nThe CVSS vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), indicating network attack vector, low attack complexity, low privilege requirements, and no user interaction required.",
"technicalDetails": "The vulnerability affects the PGC / Excel Plugin component of Oracle Agile PLM version 9.3.6.\nThe attack vector is network-based (AV:N), meaning the vulnerable service is exposed over the network and accessible via the HTTP protocol.\nThe attack complexity is rated as low (AC:L), indicating that the attacker does not require specialized conditions or complex pre-requisites to successfully execute the exploit against the target.\nThe exploitation process requires low privileges (PR:L), meaning the attacker must authenticate to the application with a low-privileged user account before launching the attack payload.\nNo user interaction is required (UI:N), allowing the attack to be executed programmatically and directly against the target component.\nThe scope is unchanged (S:U), meaning the vulnerability impacts only the immediate authorization and execution domain of the Oracle Agile PLM application.\nDuring the attack flow, the adversary leverages network access via HTTP to interact with the PGC / Excel Plugin component, submitting malicious payloads designed to bypass access controls or exhaust system resources.\nPost-exploitation impacts include unauthorized creation, deletion, or modification of critical enterprise data and all accessible Oracle Agile PLM records, leading to a severe breach of data integrity.\nFurthermore, the payload behavior induces resource exhaustion or unhandled application exceptions, precipitating a complete denial of service characterized by a system hang or frequently repeatable application crash."
}