CVE-2026-61171: Critical severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61171?
The severity of CVE-2026-61171 is critical with a CVSS score of 9.1.
How do I fix CVE-2026-61171?
To fix CVE-2026-61171, upgrade to the latest version of Oracle Agile PLM that addresses this vulnerability.
Who can exploit CVE-2026-61171?
CVE-2026-61171 can be exploited by an unauthenticated attacker with network access via HTTP.
What components are affected by CVE-2026-61171?
CVE-2026-61171 affects the Oracle Agile PLM product within the Oracle Supply Chain component.
What type of access does CVE-2026-61171 require for exploitation?
CVE-2026-61171 requires network access via HTTP for exploitation.