Sceawere

Vulnerability Detail

CVE-2026-71082UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM MCAD Connector Information Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
2.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM MCAD Connector
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data.
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.5",
  "pubDate": "2026-08-18T21:18:08.407Z",
  "pubdate": "2026-08-18T21:18:08.407Z",
  "executiveSummary": "A vulnerability exists in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically within the CAX Client component version 3.6. This security flaw is classified as a low-severity, difficult-to-exploit vulnerability that impacts data confidentiality.\nSuccessful exploitation of this vulnerability allows a low-privileged attacker who has obtained local logon access to the underlying infrastructure where the Oracle Agile PLM MCAD Connector executes to compromise the application. The primary impact is unauthorized read access to a subset of data accessible by the Oracle Agile PLM MCAD Connector.\nThe vulnerability carries a CVSS 3.1 Base Score of 2.5 with a vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N. The attack vector is local (AV:L), requiring the adversary to already possess interactive or programmatic session access to the host environment. The attack complexity is high (AC:H), indicating that specific race conditions, environmental configurations, or synchronization requirements must be met to successfully retrieve target data.\nPrivilege requirements are low (PR:L), meaning standard authenticated users lacking administrative rights can potentially mount an attack. User interaction is not required (UI:N). The scope remains unchanged (S:U), limiting the security impact strictly to the boundaries of the vulnerable component without inherently elevating privileges to compromise the wider operating system kernel or unrelated hypervisor domains. Risk implications are generally contained but remain relevant for environments processing sensitive intellectual property or proprietary engineering data within Product Lifecycle Management workflows.",
  "technicalDetails": "The vulnerability resides within the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The architectural design of the affected software fails to adequately restrict local read permissions or enforce strict discretionary access controls (DAC) over sensitive data repositories, temporary files, or inter-process communication channels utilized during computer-aided design integration operations.\nFrom an exploitation perspective, the attack flow begins with the adversary authenticating locally to the infrastructure hosting the Oracle Agile PLM MCAD Connector. Because the attack complexity is high, the threat actor must carefully orchestrate the timing and method of data access to intercept or query information handled by the CAX Client process. This may involve leveraging insecure file permissions on local caching directories, inspecting shared memory segments, or exploiting race conditions during the handling of transit data structures between CAD applications and the PLM backend.\nOnce the preconditions are satisfied and the high-complexity execution window is achieved, the low-privileged payload executes locally to read the targeted files or memory spaces. The resulting post-exploitation impact is strictly bounded to confidentiality degradation, yielding unauthorized read access to a specific subset of data accessible by the running instance of the Oracle Agile PLM MCAD Connector. The vulnerability does not grant integrity or availability impacts, preventing the attacker from modifying engineering assets, injecting malicious code, or causing denial of service conditions against the host system or PLM infrastructure."
}
CVE-2026-71082: Oracle Agile PLM MCAD Connector Information Disclosure (LOW Severity, CVSS: 2.5) - Sceawere