CVE-2026-87253: Medium severity Oracle Oracle Agile PLM vulnerability
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Agile PLM (Web Client)to a version that resolves this vulnerability.Fixed in 9.3.6
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with network access to the Oracle Agile PLM Web Client over HTTP can attempt exploitation. The attacker does not need prior access or privileges, but exploitation requires interaction from another person.
Which deployments are known to be affected?
The affected supported version identified is Oracle Agile PLM 9.3.6, specifically the Web Client component.
What could a successful attack allow?
A successful attack can provide unauthorized read access to a subset of accessible Oracle Agile PLM data and unauthorized update, insert, or delete access to some accessible data. The scope may extend to additional products.