Sceawere

Vulnerability Detail

CVE-2026-71076UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM MCAD Connector Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM MCAD Connector
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:07.727Z",
  "pubdate": "2026-08-18T21:18:07.727Z",
  "executiveSummary": "An information disclosure vulnerability has been identified within the Oracle Agile PLM MCAD Connector product, specifically affecting the CAX Client component version 3.6. This security flaw allows unauthenticated remote attackers to leverage network access via the HTTP protocol to compromise the confidentiality of the targeted system. Successful exploitation does not require user interaction or prior authentication privileges, lowering the threshold for potential attacks. The primary impact of this vulnerability is confined to confidentiality, resulting in unauthorized read access to a subset of data accessible by the Oracle Agile PLM MCAD Connector. Given the network-based vector and lack of authentication requirements, organizations utilizing the affected version face a moderate risk profile, primarily concerning the exposure of sensitive proprietary engineering or product lifecycle data. Remediation requires adherence to vendor-supplied updates or application of relevant security advisories.",
  "technicalDetails": "The vulnerability resides in the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The root cause stems from insufficient access controls or improper handling of incoming HTTP requests, which fails to adequately verify the authorization status of connecting clients before serving application data.\nExploitation of this flaw is conducted over the network using standard HTTP protocol interactions. Because the attack surface is exposed via network interfaces and the vulnerability is classified as easily exploitable with a low attack complexity, an unauthenticated threat actor can initiate direct HTTP requests to targeted endpoints within the CAX Client component without needing valid user credentials or session tokens.\nThe attack flow proceeds as follows: First, the malicious actor identifies an exposed and vulnerable instance of the Oracle Agile PLM MCAD Connector CAX Client version 3.6 via network reconnaissance. Second, the attacker crafts specific HTTP requests directed at the vulnerable interface handling data retrieval. Third, due to the absence of proper authentication and authorization checks within the component, the application processes the request and returns the requested information. Finally, the attacker receives the response containing unauthorized data payloads, achieving unauthorized read access to a subset of accessible product lifecycle management data.\nThe post-exploitation impact is strictly limited to confidentiality degradation, as indicated by the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) with a base score of 5.3. There are no integrity or availability impacts associated with this specific vulnerability vector."
}
CVE-2026-71076: Oracle Agile PLM MCAD Connector Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere