CVE-2026-71072: Low severity Oracle Oracle Agile PLM MCAD Connector vulnerability
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a low-privileged account and logon access to the infrastructure where the Oracle Agile PLM MCAD Connector runs. The attack is local and does not require user interaction.
What is the impact of successful exploitation?
Successful exploitation can cause a partial denial of service affecting Oracle Agile PLM MCAD Connector. The provided CVSS vector indicates no confidentiality or integrity impact.
Which version is identified as affected?
The affected supported version identified is 3.6.