CVE-2026-61167: Critical severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61167?
CVE-2026-61167 has a critical severity rating of 9.8.
What are the potential impacts of CVE-2026-61167?
CVE-2026-61167 allows an unauthenticated attacker to compromise Oracle Agile PLM, affecting confidentiality, integrity, and availability.
How can I mitigate CVE-2026-61167?
To mitigate CVE-2026-61167, it is recommended to apply the latest security patches provided by Oracle for the affected version.
Is CVE-2026-61167 easily exploitable?
Yes, CVE-2026-61167 is considered easily exploitable since it allows unauthenticated network access via HTTP.
Which versions of Oracle Agile PLM are affected by CVE-2026-61167?
The affected version of Oracle Agile PLM for CVE-2026-61167 is 9.3.6.