Sceawere
Vulnerability Detail
CVE-2026-71071UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM Connector Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.6
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data.
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.6",
"pubDate": "2026-08-18T21:18:07.153Z",
"pubdate": "2026-08-18T21:18:07.153Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Oracle Agile PLM MCAD Connector product, specifically affecting the CAX Client component version 3.6. This security flaw enables a low-privileged attacker with physical communication segment access to compromise the targeted software. Successful exploitation yields unauthorized read, update, insert, and delete access to a subset of accessible data within the Oracle Agile PLM MCAD Connector. The vulnerability carries a CVSS 3.1 Base Score of 4.6, indicating moderate risk primarily affecting confidentiality and integrity without impacting system availability.",
"technicalDetails": "The vulnerability resides in the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The root cause stems from insufficient security controls within the local communication mechanisms utilized by the application. Because the attack vector is categorized as Adjacent (AV:A), the adversary must be positioned on the exact physical communication segment attached to the hardware hosting the Oracle Agile PLM MCAD Connector execution environment.\nExploitation requires low privileges (PR:L) and no user interaction (UI:N), but relies on the attacker's ability to intercept or manipulate traffic traversing the local physical communication segment. Upon successful positioning within the required network segment, the attacker can leverage the flaw to interact with unsecured communication channels or exposed local interfaces. This allows malicious payloads or unauthorized commands to be injected into the data stream processed by the CAX Client.\nThe post-exploitation impact includes unauthorized data exposure (Confidentiality impact) and unauthorized data tampering (Integrity impact). Specifically, an attacker can execute unauthorized read operations to harvest sensitive information, as well as perform unauthorized updates, insertions, or deletions of accessible data within the scope of the Oracle Agile PLM MCAD Connector. The vulnerability does not cause denial of service conditions, leaving system availability uncompromised."
}