Sceawere
Vulnerability Detail
CVE-2026-71083UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM MCAD Connector Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 1.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "1.8",
"pubDate": "2026-08-18T21:18:08.523Z",
"pubdate": "2026-08-18T21:18:08.523Z",
"executiveSummary": "An information disclosure vulnerability affects the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically within the CAX Client component version 3.6. This vulnerability allows an authenticated attacker with high privileges and local access to the target infrastructure to compromise the application and gain unauthorized read access to a subset of sensitive data. Exploitation of this security flaw is classified as difficult and requires specific preconditions, most notably requiring interactive human participation from a user other than the attacker. Despite the elevated privilege requirement, the impact is strictly limited to confidentiality, resulting in low overall severity as denoted by a CVSS 3.1 Base Score of 1.8. The attack vector is localized, requiring physical or remote interactive logon to the underlying infrastructure where the affected component executes. Organizations utilizing the affected software version must evaluate local privilege boundaries and enforce strict user interaction controls to mitigate potential unauthorized data exposure risks within the Agile PLM ecosystem.",
"technicalDetails": "The vulnerability resides in the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. From an architectural and privilege standpoint, the flaw requires the attacker to possess high privileges and interactive logon access to the host infrastructure where the vulnerable software executes, corresponding to an Attack Vector (AV) of Local and High Privilege Requirements (PR:H). The vulnerability exhibits high Attack Complexity (AC:H), indicating that successful exploitation relies on non-standard race conditions, specific system configurations, or precise timing windows. Furthermore, the attack vector mandates User Interaction (UI:R), meaning that a secondary user other than the attacker must perform an action to facilitate the execution chain. The attack flow begins with the high-privileged adversary establishing an authorized interactive session on the host operating system hosting the CAX Client. The attacker then manipulates the local environment or execution context of the Oracle Agile PLM MCAD Connector component. Because successful exploitation necessitates human interaction, the attacker must induce another system user to execute or interact with a manipulated process, file, or interface associated with the CAX Client. Upon successful execution of these prerequisite steps, the vulnerability triggers an unintended information disclosure vector. The scope (S:U) of the vulnerability remains unchanged, meaning the security bounds do not cross beyond the local application context. The post-exploitation impact is constrained exclusively to confidentiality (C:L), granting the adversary unauthorized read access to a specific subset of data accessible by the Oracle Agile PLM MCAD Connector. There are no direct impacts on system integrity (I:N) or availability (A:N). The combination of local access constraints, high execution privileges, high complexity, and required user interaction significantly reduces the probability of automated or widespread exploitation in real-world enterprise environments."
}