CVE-2026-71042: High severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Agile PLM (PGC / Excel Plugin)to a version that resolves this vulnerability.Fixed in 9.3.6
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-privileged access to Oracle Agile PLM and network access to the affected system via HTTP. No user interaction is required.
Which deployments are known to be affected?
The affected component is PGC / Excel Plugin in Oracle Agile PLM version 9.3.6. The provided information does not identify affected default configurations or additional versions.
What could a successful attack allow?
A successful attacker could create, delete, or modify critical data or all data accessible through Oracle Agile PLM. They could also cause the application to hang or repeatedly crash, resulting in complete denial of service.