CVE-2026-21940: Infoleak
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21940?
CVE-2026-21940 is considered easily exploitable, allowing an unauthenticated attacker to compromise Oracle Agile PLM.
How do I fix CVE-2026-21940?
To fix CVE-2026-21940, upgrade to the latest patched version of Oracle Agile PLM.
Who is affected by CVE-2026-21940?
CVE-2026-21940 affects users running Oracle Agile PLM version 9.3.6.
What components are involved in CVE-2026-21940?
CVE-2026-21940 impacts the User and User Group components of Oracle Agile PLM.
Can CVE-2026-21940 be exploited remotely?
Yes, CVE-2026-21940 can be exploited remotely via network access using HTTP.