Sceawere
Vulnerability Detail
CVE-2026-71089UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM MCAD Connector Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.3
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.3",
"pubDate": "2026-08-18T21:18:09.087Z",
"pubdate": "2026-08-18T21:18:09.087Z",
"executiveSummary": "An information disclosure vulnerability has been identified within the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically affecting the CAX Client component version 3.6. This security flaw enables an unauthenticated attacker who has local logon access to the underlying infrastructure where the software executes to compromise the application and achieve unauthorized read access to a subset of sensitive data. Exploitation of this vulnerability requires local access combined with social engineering or user interaction from a third party other than the attacker, limiting the immediacy of remote exploitation vectors. The resulting impact is strictly confined to confidentiality breaches, as indicated by a CVSS 3.1 Base Score of 3.3 with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N. Organizations deploying the affected version face risks regarding the unauthorized exposure of proprietary engineering and product lifecycle management data stored or processed within the local environment. Mitigating this risk requires restricting local infrastructure access, enforcing strict privilege management, and applying available vendor patches or security advisories.",
"technicalDetails": "The vulnerability resides in the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. The root cause stems from insecure handling of local resources or improper access control enforcement within the application execution environment, which permits unauthorized data retrieval under specific operational states. Because the attack vector (AV:L) is local, the adversary must already possess interactive logon capabilities to the host operating system or virtualized infrastructure where the CAX Client executes. However, the attack complexity (AC) is rated as low, indicating that once local execution context or access is achieved, no advanced race conditions or complex exploitation primitives are required to trigger the flaw. The vulnerability requires explicit user interaction (UI:R) from a distinct individual other than the attacker, implying that successful execution of the attack flow relies on a victim performing an action—such as opening a maliciously crafted file, initiating a specific software workflow, or interacting with a compromised local interface—that inadvertently exposes the target data subset. Upon successful exploitation, the payload or attack mechanism facilitates unauthorized read access (C:L) to localized data accessible by the Oracle Agile PLM MCAD Connector. Integrity and availability metrics remain unaffected (I:N, A:N), confirming that the vulnerability does not allow data modification, destruction, or denial of service against the host system or application services. The scope (S:U) remains unchanged, meaning the security impact is contained within the immediate local authorization boundary of the vulnerable component. Post-exploitation impact is limited to the exfiltration or viewing of sensitive engineering data residing within the accessible data subsets of the affected CAX Client installation, potentially compromising intellectual property or proprietary design information handled by the PLM ecosystem."
}