CVE-2026-61170: High severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Agile PLM (Oracle Supply Chain)to a version that resolves this vulnerability.Fixed in 9.3.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61170?
The severity of CVE-2026-61170 is classified as high with a score of 8.1.
How do I fix CVE-2026-61170?
To fix CVE-2026-61170, upgrade to the latest supported version of Oracle Agile PLM, specifically beyond version 9.3.6.
What systems are affected by CVE-2026-61170?
CVE-2026-61170 affects the Oracle Agile PLM product, specifically version 9.3.6.
What type of attack does CVE-2026-61170 enable?
CVE-2026-61170 allows an unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.
Is CVE-2026-61170 difficult to exploit?
CVE-2026-61170 is considered a difficult to exploit vulnerability.