Sceawere
Vulnerability Detail
CVE-2026-71068UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM Connector Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM MCAD Connector.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-18T21:18:06.783Z",
"pubdate": "2026-08-18T21:18:06.783Z",
"executiveSummary": "A remotely exploitable security vulnerability affects the Oracle Agile PLM MCAD Connector product within Oracle Supply Chain, specifically residing in the CAX Client component version 3.6. This vulnerability permits an unauthenticated threat actor with network access to compromise the targeted system entirely via HTTP protocol interactions.\nSuccessful exploitation of this flaw grants an attacker the ability to achieve a full system takeover of the affected Oracle Agile PLM MCAD Connector instance, resulting in severe impacts across all three pillars of the CIA triad: confidentiality, integrity, and availability. The assigned CVSS 3.1 base score is 8.1, reflecting the critical nature of the potential damage despite the high attack complexity metric defined in the vector.\nThe attack vector is network-based (AV:N), requiring zero user interaction (UI:N) and no prior privileges (PR:N). However, the attack complexity is rated as high (AC:H), implying that successful execution may depend on specific environmental conditions or specialized exploitation techniques. Organizations utilizing the specified version face significant risk, as a successful compromise allows unauthorized entities to manipulate engineering data, disrupt supply chain operations, and compromise underlying server resources.",
"technicalDetails": "The vulnerability resides within the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The application exposes an HTTP-based interface accessible via the network, which processes incoming requests without adequate validation or access controls. Because the flaw allows unauthenticated remote exploitation, external entities can interact directly with vulnerable endpoints exposed by the service.\nThe attack flow begins when an unauthenticated attacker leverages network connectivity to send a maliciously crafted HTTP payload targeting the vulnerable CAX Client interface. Although the attack complexity is classified as high, successful exploitation typically involves bypassing input filters, exploiting insecure deserialization routines, or abusing improper authorization checks within the request handling logic of the CAX Client.\nUpon receipt of the malicious payload, the vulnerable component processes the input insecurely, leading to memory corruption, arbitrary code execution, or unauthorized command injection depending on the exact underlying flaw. Because the application runs with elevated system permissions necessary for managing PLM and MCAD integrations, successful execution of the payload allows the attacker to hijack the execution flow of the process.\nPost-exploitation impact includes a complete takeover of the Oracle Agile PLM MCAD Connector. The attacker gains the ability to read, modify, or delete sensitive engineering and product lifecycle management data, install persistent backdoors, pivot deeper into the corporate network, and disrupt core supply chain availability. The combination of unauthenticated network access and high severity impacts on confidentiality, integrity, and availability makes this a critical security concern for affected deployments."
}