Sceawere

Vulnerability Detail

CVE-2026-71087UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Agile PLM MCAD Connector Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Agile PLM MCAD Connector
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:08.860Z",
  "pubdate": "2026-08-18T21:18:08.860Z",
  "executiveSummary": "An information disclosure vulnerability affects the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically within the CAX Client component version 3.6. This security flaw enables an unauthenticated remote attacker with network access via the HTTP protocol to compromise the confidentiality of the target system without requiring user interaction.\nSuccessful exploitation of this vulnerability results in unauthorized read access to a subset of data accessible by the Oracle Agile PLM MCAD Connector. The vulnerability carries a CVSS 3.1 Base Score of 5.3, with impacts exclusively affecting confidentiality (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The risk implications include the potential exposure of sensitive engineering and product lifecycle management data to unauthorized third parties.\nThe attack vector is network-based with low attack complexity, requiring no privileges or user interaction, making it an easily exploitable flaw for any adversary capable of reaching the HTTP service exposed by the vulnerable CAX Client component.",
  "technicalDetails": "The vulnerability resides within the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The root cause stems from improper access controls or insecure data handling within the application logic exposed over HTTP, which fails to properly validate the identity or authorization level of incoming client requests before serving stored or processed engineering data.\nAttackers initiate the attack flow by leveraging network access to communicate directly with the HTTP service hosted by the vulnerable Oracle Agile PLM MCAD Connector. Because the vulnerability requires no authentication or privileges (PR:N, UI:N), the attacker can issue crafted HTTP requests directly to the target endpoints without needing prior credentials or session tokens.\nUpon receiving the unauthorized request, the vulnerable CAX Client component processes the query and improperly returns a subset of accessible data in the HTTP response payload. This post-exploitation impact is strictly confined to confidentiality degradation (C:L), as the flaw does not permit data modification, deletion, or execution of arbitrary code, nor does it impact system integrity or availability.\nThe network exposure (AV:N) and low attack complexity (AC:L) dictate that any host with IP connectivity to the affected HTTP listener can trigger the vulnerability. Remediation analysis requires identifying the specific endpoints handling the requests within the CAX Client component and applying stringent access control enforcement to ensure only authenticated and authorized principals can retrieve protected data subsets."
}
CVE-2026-71087: Oracle Agile PLM MCAD Connector Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere