Sceawere
Vulnerability Detail
CVE-2026-71077UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM MCAD Connector Confidentiality Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data.
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-18T21:18:07.837Z",
"pubdate": "2026-08-18T21:18:07.837Z",
"executiveSummary": "A vulnerability affects the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically within the CAX Client component, version 3.6. This security flaw is classified as a difficult-to-exploit vulnerability that allows an unauthenticated attacker to compromise the target system and gain unauthorized access to critical data. The risk implication is significant regarding data confidentiality, as successful exploitation can yield complete access to all data accessible by the Oracle Agile PLM MCAD Connector. Exploitation requirements dictate that the attacker must have physical access to the specific communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes. Despite the difficulty of exploitation due to high attack complexity and specific physical network segment requirements, the potential impact on data confidentiality remains high, as reflected by the CVSS 3.1 Base Score of 5.3 with a vector of CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N.",
"technicalDetails": "The vulnerability resides within the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The root cause stems from insufficient security controls or inadequate cryptographic protections during communication across the local hardware communication segment, allowing unauthorized interception or interaction.\nThe attack vector is categorized as adjacent (AV:A), meaning the attacker must be physically or logically proximate to the target system's local communication segment to mount an exploit. The attack complexity is rated as high (AC:H), indicating that successful exploitation requires specialized conditions, precise timing, or complex configuration manipulation by the adversary.\nRegarding authentication and privileges, the vulnerability requires no authentication (PR:N) and no user interaction (UI:N). An unauthenticated threat actor who successfully bridges or accesses the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes can initiate the attack sequence.\nThe step-by-step attack flow involves the adversary establishing physical or local link-layer access to the targeted hardware communication segment. Once positioned on the correct segment, the attacker monitors, intercepts, or injects traffic intended for the CAX Client component. Due to the underlying flaw in how the Oracle Agile PLM MCAD Connector processes or secures data transactions on this segment, the attacker bypasses standard access barriers without needing valid credentials.\nThe post-exploitation impact is strictly confined to confidentiality (C:H), resulting in unauthorized disclosure of critical enterprise data or complete access to all data accessible by the Oracle Agile PLM MCAD Connector instance. Integrity and availability impacts remain unaffected (I:N, A:N)."
}