CVE-2026-61172: High severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61172?
The severity of CVE-2026-61172 is rated as high with a score of 7.5.
How do I fix CVE-2026-61172?
To fix CVE-2026-61172, apply the latest security patch provided by Oracle for Agile PLM version 9.3.6.
Who is affected by CVE-2026-61172?
Organizations using Oracle Agile PLM version 9.3.6 are affected by CVE-2026-61172.
What are the risks associated with CVE-2026-61172?
CVE-2026-61172 poses a risk of unauthenticated attackers compromising Oracle Agile PLM via network access.
What component of Oracle is impacted by CVE-2026-61172?
CVE-2026-61172 impacts the security component of the Oracle Agile PLM product.