Sceawere
Vulnerability Detail
CVE-2026-71088UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM MCAD Connector Confidentiality Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.8",
"pubDate": "2026-08-18T21:18:08.973Z",
"pubdate": "2026-08-18T21:18:08.973Z",
"executiveSummary": "A security vulnerability has been identified within the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically affecting the CAX Client component version 3.6. This vulnerability allows a low-privileged remote attacker with network access via HTTP to compromise the confidentiality of the application.\nThe vulnerability carries a CVSS 3.1 Base Score of 4.8 with a vector of CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N, indicating that exploitation is difficult and primarily impacts data confidentiality without affecting integrity or availability.\nSuccessful exploitation requires specific attack conditions, including low-privileged authentication, network connectivity via HTTP, and mandatory human interaction from a user other than the attacker. When successfully executed, the attack grants the adversary unauthorized access to critical data or complete access to all data accessible via the Oracle Agile PLM MCAD Connector.\nOrganizations utilizing the affected Oracle Supply Chain component face risks of sensitive data exposure. Mitigation requires adhering to vendor advisories and applying official patches or configuration hardening to restrict unauthorized data access channels.",
"technicalDetails": "The vulnerability resides in the CAX Client component of the Oracle Agile PLM MCAD Connector product, specifically within version 3.6. The architectural design of this component processes network-based requests over the HTTP protocol, exposing internal data handling logic to authenticated users.\nAttack execution requires the threat actor to possess low-privileged network access to the target system. Due to the high attack complexity (AC:H) and the necessity for user interaction (UI:R), the attacker cannot achieve compromise entirely autonomously. Instead, the attack flow typically involves social engineering or deceptive interaction mechanisms directed at a secondary user of the system to trigger the vulnerable code path or data retrieval operation.\nDuring the attack flow, the low-privileged attacker leverages HTTP communication channels to interact with the vulnerable CAX Client component. Upon successful inducement of the required human interaction, the application improperly handles access control or data exposure constraints, inadvertently disclosing sensitive information to the unauthorized entity.\nThe resulting impact is strictly limited to the confidentiality vector (C:H), yielding unauthorized access to critical data repositories or complete access to all data accessible through the Oracle Agile PLM MCAD Connector interface. Integrity (I:N) and Availability (A:N) metrics remain unaffected, as the vulnerability does not facilitate data modification, deletion, or denial of service conditions."
}