CVE-2026-61173: High severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Agile PLM (Oracle Supply Chain) - Security componentto a version that resolves this vulnerability.Fixed in 9.3.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61173?
The severity of CVE-2026-61173 is rated as high with a score of 7.4.
How do I fix CVE-2026-61173?
To fix CVE-2026-61173, update your Oracle Agile PLM software to the latest patched version.
What component of Oracle Agile PLM is affected by CVE-2026-61173?
CVE-2026-61173 affects the security component of the Oracle Agile PLM product.
Who is at risk from CVE-2026-61173?
Unauthenticated attackers with network access via HTTP are at risk from exploiting CVE-2026-61173.
What is the difficulty level for exploiting CVE-2026-61173?
CVE-2026-61173 is classified as a difficult to exploit vulnerability.