CVE-2026-46859: Critical severity Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46859?
CVE-2026-46859 has a critical severity rating of 9.8.
How do I fix CVE-2026-46859?
To fix CVE-2026-46859, upgrade Oracle Agile PLM to the latest version that addresses this vulnerability.
What products are affected by CVE-2026-46859?
CVE-2026-46859 affects the Oracle Agile PLM product, specifically version 9.3.6.
Who can exploit CVE-2026-46859?
CVE-2026-46859 can be exploited by unauthenticated attackers with network access via HTTP.
What impact can CVE-2026-46859 have on an organization?
Successful exploitation of CVE-2026-46859 can lead to a complete compromise of Oracle Agile PLM, affecting confidentiality, integrity, and availability.